Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1166 results
connectwise-screenconnect_auth-bypass-add-user-poc preview

connectwise-screenconnect_auth-bypass-add-user-poc

GitHubwatchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc

Proof-of-concept exploit for authentication bypass in ConnectWise ScreenConnect, enabling addition of administrative user as first step to Remote…

authentication-authorizationexploitationprivilege-escalation+3
75
2 years ago
CVE-2023-46805_CVE-2024-21887 preview

CVE-2023-46805_CVE-2024-21887

GitHubduy-31/cve-2023-46805_cve-2024-21887

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access…

authentication-authorizationcommand-and-controlexploitation+3
232 years ago
CVE-2024-27198-POC preview

CVE-2024-27198-POC

GitHubeynaexp/cve-2024-27198-poc

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

authenticationexploitationpenetration-testing+3
18 months ago
cve-2026-21509-office_security_bypass_reproduction preview

cve-2026-21509-office_security_bypass_reproduction

GitHubrazureink/cve-2026-21509-office_security_bypass_reproduction

CVE Reproduction: cve-2026-21509-office_security_bypass_reproduction

binary-exploitationeducationexploitation+5
1 month ago
jboss-autopwn preview

jboss-autopwn

GitHubgitcollect/jboss-autopwn

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

command-and-controlexploitationpayload-development+4
110 years ago
CVE-2024-21546 preview

CVE-2024-21546

GitHubajdumanhug/cve-2024-21546

This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions…

exploitationpayload-generationpenetration-testing+3
51 year ago
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass preview

the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

GitHubhunt-benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

api-securityauthenticationexploitation+3
9 days ago
CVE-2025-29927-Nextjs-Bypass-PoC preview

CVE-2025-29927-Nextjs-Bypass-PoC

GitHubdanielhallbro/cve-2025-29927-nextjs-bypass-poc

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

authenticationeducationexploitation+3
17 months ago
CVE-2022-28601 preview

CVE-2022-28601

GitHubflaviupopescu/cve-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationexploitationpenetration-testing+2
84 years ago
DOLIBARR-RCE-CVE-2026-22666 preview

DOLIBARR-RCE-CVE-2026-22666

GitHubjivasecurity/dolibarr-rce-cve-2026-22666

dol_eval_standard() whitelist bypass eval() RCE, affecting Dolibarr 23.0.0 and below by jiva (jivasecurity.com)

code-analysisexploitationpenetration-testing+2
5 months ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
CVE-2025-9209 preview

CVE-2025-9209

GitHubnxploited/cve-2025-9209

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

authentication-authorizationexploitationinformation-gathering+5
10 months ago
oracle-oam-authentication-bypas-exploit preview

oracle-oam-authentication-bypas-exploit

GitHubaymanelsherif/oracle-oam-authentication-bypas-exploit

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

authentication-authorizationcryptographyexploitation+3
77 years ago
cve-2026-43515-poc preview

cve-2026-43515-poc

GitHubcovepseng/cve-2026-43515-poc

Exploitability PoC for CVE-2026-43515 (Apache Tomcat constraint bypass).

authenticationeducationexploitation+3
2 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubwhattheslime/cve-2026-8181

Exploit for the CVE-2026-8181 - Burst Statistics WordPress Plugin Authentication Bypass

authenticationexploitationpenetration-testing+3
3 months ago
CVE-2021-21014 preview

CVE-2021-21014

GitHubhoangkien1020/cve-2021-21014

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful…

code-analysisexploitationpenetration-testing+2
45 years ago
CVE-2023-24329-Exploit preview

CVE-2023-24329-Exploit

GitHubpentestmano/cve-2023-24329-exploit

Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
1 month ago
Previous1234…65Next