Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
CVE-2024-2044 preview

CVE-2024-2044

GitHubhanzzly/cve-2024-2044

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…

exploitationpayload-developmentpenetration-testing+5
1 day ago
metasploit-pentest-report preview

metasploit-pentest-report

GitHubronankongala/metasploit-pentest-report

Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings…

ctfcurated-resourceseducation+7
15 days ago
CVE-2025-2945-pgAdmin-RCE preview

CVE-2025-2945-pgAdmin-RCE

GitHubkhashayarnzk/cve-2025-2945-pgadmin-rce

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

exploitationpenetration-testingremote-access-tool+2
18 days ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4 months ago
cPanelSniper preview

cPanelSniper

GitHubynsmroztas/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4994 months ago
CVE-2026-31431-CopyFail-Universal-LPE preview

CVE-2026-31431-CopyFail-Universal-LPE

GitHubshadowabi/cve-2026-31431-copyfail-universal-lpe

CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback

binary-exploitationcontainer-securityexploitation+6
584 months ago
copy-fail-CVE-2026-31431 preview

copy-fail-CVE-2026-31431

GitHubrio128128/copy-fail-cve-2026-31431

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

binary-exploitationcloud-securitycontainer-security+6
4 months ago
cPanelWHM-AuthBypass preview

cPanelWHM-AuthBypass

GitHubkagantua/cpanelwhm-authbypass

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

authenticationexploitationpenetration-testing+3
114 months ago
copy-fail_LPE_Interactive preview

copy-fail_LPE_Interactive

GitHubh1d3r/copy-fail_lpe_interactive

Exploit for CVE-2026-31431, a Linux kernel page cache corruption vulnerability, providing interactive root shell and non-interactive command…

binary-exploitationexploitationexploit-frameworks+3
4 months ago
CVE-2026-12948 preview

CVE-2026-12948

GitHubnvicloud/cve-2026-12948

Proof of concept for stored XSS in Digi PortServer TS 4 H MEI web interface, demonstrating persistent payload execution and providing remediation…

exploitationpenetration-testingvulnerability-analysis+2
2 months ago
By-Poloss..-..CVE-2026-15038-POC preview

By-Poloss..-..CVE-2026-15038-POC

GitHubpolosss/by-poloss..-..cve-2026-15038-poc

POC 4 CVE-2026-15038

authenticationexploitationpenetration-testing+3
11 month ago
deploy-goad preview

deploy-goad

GitHublkarlslund/deploy-goad

Script to install prerequisites for deploying GOAD on Ubuntu Linux 22.04

educationlabs-practicepenetration-testing+1
1162 years ago
TOTPAuthenticate preview

TOTPAuthenticate

GitHubhannah-portswigger/totpauthenticate

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

api-security-testingauthenticationpenetration-testing+1
92 years ago
EvilCrowRF_Custom_Firmware_CC1101_FlipperZero preview

EvilCrowRF_Custom_Firmware_CC1101_FlipperZero

GitHubh-rat/evilcrowrf_custom_firmware_cc1101_flipperzero

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

embedded-systems-securityhardware-hackinghardware-iot-security+5
5992 years ago
CVE-2026-63223 preview

CVE-2026-63223

GitHubshinthink/cve-2026-63223

CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434…

exploitationpayload-generationpenetration-testing+3
21 month ago
CVE-2026-17566 preview

CVE-2026-17566

GitHubhackspeak/cve-2026-17566

pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch

exploitationpayload-generationpenetration-testing+3
11 month ago
CVE-2026-63223-POC preview

CVE-2026-63223-POC

GitHubimbas007/cve-2026-63223-poc

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

educationexploitationlabs-practice+5
31 month ago
pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass preview

pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass

GitHubhunt-benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass

Proof-of-concept demonstrating CVE-2026-17351 SQL injection bypass in pgAdmin 4's AI Assistant via sqlparse/PostgreSQL lexer differential, including…

ai-securitydatabase-securityeducation+4
1 month ago
Previous12345Next