Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
CVE-2026-22599 preview

CVE-2026-22599

GitHubabraxas/cve-2026-22599

Python PoC and Docker lab for CVE-2026-22599, an authenticated SQL injection in Strapi's Content-Type Builder write API via Knex raw defaultTo.

database-securityexploitationlabs-practice+5
1
5 days ago
CVE-2026-77635 preview

CVE-2026-77635

GitHubabraxas/cve-2026-77635

Disclosure pack and Python PoC for CVE-2026-77635, an unauthenticated SQL injection in CakePHP's jsonValue() with PostgresDriver, including a…

database-securityexploitationlabs-practice+5
5 days ago
CVE-2026-79752 preview

CVE-2026-79752

GitHubabraxas/cve-2026-79752

CVE-2026-79752 disclosure pack for CakePHP 5.2.13 SQL injection via FunctionsBuilder::cast, with a Python PoC script and Docker lab for authorized…

database-securityeducationexploitation+6
5 days ago
CVE-2026-67401 preview

CVE-2026-67401

GitHubimbas007/cve-2026-67401

Proof-of-concept for CVE-2026-67401, a cPanel/WHM EmailTrack SQL injection enabling arbitrary file write and root RCE, with SQLi detection probes and…

educationexploitationlabs-practice+5
519 days ago
CVE-2026-44840-poc preview

CVE-2026-44840-poc

GitHubisaca0315/cve-2026-44840-poc

Docker lab reproducing CVE-2026-44840, a DQL injection in Dgraph's checkUserPassword GraphQL query, with exploit script and vulnerable vs patched…

database-securityexploitationlabs-practice+5
19 days ago
POC-AIOWPM-CVE-2026-19949 preview

POC-AIOWPM-CVE-2026-19949

GitHub686f6c61/poc-aiowpm-cve-2026-19949

Reproducible Docker-based proof-of-concept for CVE-2026-19949, a second-order SQL injection in All-in-One WP Migration <= 7.109 that leaks the…

educationexploitationlabs-practice+4
420 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
20 days ago
CVE-2026-76461 preview

CVE-2026-76461

GitHub0xblackash/cve-2026-76461

Research repository for CVE-2026-76461, a critical SQL injection in Cisco Secure Email Gateway leading to root RCE, with detection rules, mitigation…

educationemail-securityexploitation+7
220 days ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
22 days ago
H2-database-CVE-2022-23221 preview

H2-database-CVE-2022-23221

GitHubstraightsang/h2-database-cve-2022-23221

vulhub/H2-database/CVE-2022-23221

database-securityeducationexploitation+3
25 days ago
CVE-2023-25157 preview

CVE-2023-25157

GitHubivanesk315/cve-2023-25157

Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.

database-securityeducationexploitation+6
26 days ago
CVE-2026-76904 preview

CVE-2026-76904

GitHubyonliud/cve-2026-76904

One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE

educationexploitationlabs-practice+4
51 month ago
CVE-2026-26980 preview

CVE-2026-26980

GitHubyym8538/cve-2026-26980

Python PoC and Docker lab demonstrating unauthenticated SQL injection in TryGhost Ghost CMS Content API slug filter, extracting database values via a…

database-securityeducationexploitation+5
11 month ago
DB_Audit_Research preview

DB_Audit_Research

GitHubmthamil107/db_audit_research

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

adversarial-attackdatabase-securitydefensive-tools+4
1 month ago
CVE-2026-14669 preview

CVE-2026-14669

GitHubhackspeak/cve-2026-14669

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

binary-exploitationdatabase-securityexploitation+4
31 month ago
POC-GeoLeak-CVE-2026-52715 preview

POC-GeoLeak-CVE-2026-52715

GitHub686f6c61/poc-geoleak-cve-2026-52715

PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit…

educationexploitationlabs-practice+4
1 month ago
e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout preview

e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

GitHubhunt-benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

database-securityeducationexploitation+4
12 months ago
POC-CVE-2026-58048 preview

POC-CVE-2026-58048

GitHubimbas007/poc-cve-2026-58048

Security research project

database-securityexploitationlabs-practice+4
22 months ago
Previous1234567Next