Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
256 results
Lab4PurpleSec preview

Lab4PurpleSec

GitHub0xmr007/lab4purplesec

Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense +…

educationids-ips-evasionintrusion-detection+5
328
8 months ago
LOAD preview

LOAD

GitHub0xballpoint/load

Lord Of Active Directory - automatic vulnerable active directory on AWS

cloud-infrastructure-securityeducationlabs-practice+3
1562 years ago
CVE-2023-0386-go-poc preview

CVE-2023-0386-go-poc

GitHubhuovnn/cve-2023-0386-go-poc

Go proof-of-concept for CVE-2023-0386, using FUSE and overlayfs to escalate an unprivileged user to root on vulnerable Linux systems.

exploitationpenetration-testingpost-exploitation+3
6 months ago
CVE-2021-3560-PolkitPrivilegeEsclation preview

CVE-2021-3560-PolkitPrivilegeEsclation

GitHubyutasato88/cve-2021-3560-polkitprivilegeesclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

exploitationpenetration-testingpost-exploitation+3
4 months ago
ad-honeypot-autodeploy preview

ad-honeypot-autodeploy

GitHubtothi/ad-honeypot-autodeploy

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

educationlabs-practicelog-analysis+3
2593 years ago
CrushFTP-auth-bypass-CVE-2025-31161 preview

CrushFTP-auth-bypass-CVE-2025-31161

GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

authentication-authorizationcommand-and-controlctf+7
11 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubmurrez/cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass chain in WHM/cPanel. Multi-threaded scanner that changes root password on…

authentication-authorizationexploitationpenetration-testing+3
53 months ago
CVE-2024-27198-RCE preview

CVE-2024-27198-RCE

GitHubw01fh4cker/cve-2024-27198-rce

CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4

authentication-authorizationexploitationpenetration-testing+3
1542 years ago
RCity-CVE-2024-27198 preview

RCity-CVE-2024-27198

GitHubstuub/rcity-cve-2024-27198

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

authentication-authorizationeducationexploitation+4
352 years ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
26 days ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubk3ystr0k3r/cve-2026-24061

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

authenticationauthentication-authorizationcommand-and-control+8
32 months ago
CVE-2026-4484 preview

CVE-2026-4484

GitHubnxploited/cve-2026-4484

Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

authentication-authorizationexploitationpenetration-testing+4
4 months ago
CVE-2026-1937 preview

CVE-2026-1937

GitHubnxploited/cve-2026-1937

YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action

authentication-authorizationexploitationpenetration-testing+4
4 months ago
CVE-2025-14440 preview

CVE-2025-14440

GitHubnxploited/cve-2025-14440

JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

authentication-authorizationexploitationpenetration-testing+3
18 months ago
CVE-2026-48611-EXPLOIT preview

CVE-2026-48611-EXPLOIT

GitHubdiznev/cve-2026-48611-exploit

CVE-2026-48611- authentication bypass in phpBB

authentication-authorizationexploitationpenetration-testing+3
2 months ago
CVE-2025-8359 preview

CVE-2025-8359

GitHubnxploited/cve-2025-8359

AdForest <= 6.0.9 - Authentication Bypass to Admin

authentication-authorizationexploitationpenetration-testing+2
11 months ago
CVE-2025-8570 preview

CVE-2025-8570

GitHubnxploited/cve-2025-8570

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

authentication-authorizationeducationexploitation+6
11 months ago
CVE-2026-65400-poc preview

CVE-2026-65400-poc

GitHubpanchocosil/cve-2026-65400-poc

Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9…

authentication-authorizationexploitationpenetration-testing+3
28 days ago
Previous12…15Next