Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
99 results
CVE-2026-57821-PoC-Exploit preview

CVE-2026-57821-PoC-Exploit

GitHubtc4dy/cve-2026-57821-poc-exploit

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

code-analysisdatabase-securityeducation+5
3
2 months ago
CVE-2020-7471-Django preview

CVE-2020-7471-Django

GitHubhuzaifakhan771/cve-2020-7471-django

PoC for the SQL injection vulnerability in PostgreSQL with Django, found in Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3

code-analysisdatabase-securityeducation+3
15 years ago
CVE-2024-43018 preview

CVE-2024-43018

GitHubjoaosilva21/cve-2024-43018

Proof-of-concept for CVE-2024-43018: SQL injection in Piwigo 13.8.0 via unsanitized max_level and min_register parameters, enabling information…

code-analysisinformation-gatheringpenetration-testing+2
1 year ago
CVE-2021-31856 preview

CVE-2021-31856

GitHubssst0n3/cve-2021-31856

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

code-analysisdatabase-securitypenetration-testing+2
5 years ago
lua-ffi-libinjection preview

lua-ffi-libinjection

GitHubp0pr0ck5/lua-ffi-libinjection

LuaJIT FFI bindings for libinjection, providing SQL injection and XSS detection with context-specific APIs for web application security.

api-securitycode-analysisstatic-analysis+2
388 years ago
CVE-2021-43609-POC preview

CVE-2021-43609-POC

GitHubd5sec/cve-2021-43609-poc

Proof-of-concept exploit for CVE-2021-43609 demonstrating SQL injection to file read to remote code execution chain against Spiceworks help desk…

code-analysisexploitationpayload-development+3
52 years ago
CVE-2026-51992 preview

CVE-2026-51992

GitHubtheliimbo/cve-2026-51992

Proof-of-concept and detailed writeup for CVE-2026-51992, an SQL injection vulnerability in ClickHouse PostgreSQL dictionaries allowing arbitrary…

code-analysisdatabase-securityeducation+3
2 months ago
CVE-2024-39306 preview

CVE-2024-39306

GitHubapena-ba/cve-2024-39306

Proof-of-concept exploit for CVE-2024-39306, a SQL injection vulnerability in ChurchCRM <= 5.8.0 that allows authenticated remote code execution.…

code-analysisexploitationpenetration-testing+2
12 years ago
CVE-2024-39304 preview

CVE-2024-39304

GitHubapena-ba/cve-2024-39304

Proof-of-concept exploit for CVE-2024-39304, a SQL injection vulnerability in ChurchCRM, allowing authenticated attackers to execute arbitrary SQL…

code-analysisexploitationpenetration-testing+2
12 years ago
CVE-2023-38890 preview

CVE-2023-38890

GitHubtagoletta/cve-2023-38890

Exploit for CVE-2023-38890, an unauthenticated SQL injection to remote code execution in Online Shopping Portal 3.1, with a proof-of-concept and…

code-analysisexploitationpenetration-testing+2
8 months ago
CVE-2024-1207 preview

CVE-2024-1207

GitHubsahar042/cve-2024-1207

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all…

code-analysisexploitationpenetration-testing+3
1 year ago
CVE-2025-8971 preview
Archived

CVE-2025-8971

GitHubbytereaper77/cve-2025-8971

Sql injection in itsourcecode Online Tour and Travel Management System 1.0.

code-analysisexploitationpayload-generation+3
11 year ago
CVE-2022-28171-POC preview

CVE-2022-28171-POC

GitHubnyameeeain/cve-2022-28171-poc

Python exploit for CVE-2022-28171 targeting Hikvision Hybrid SAN devices, automating blind SQL injection and command injection to achieve remote code…

code-analysisexploitationiot-security+3
43 years ago
CVE-2024-27766 preview

CVE-2024-27766

GitHuby0un9eee/cve-2024-27766

Modified PoC for MariaDB v11.1 RCE via UDF, returning command output inline through SQL queries. Includes detailed code comparison and compilation…

binary-exploitationcode-analysisdatabase-security+4
5 months ago
wp2shell-lab preview

wp2shell-lab

GitHub47cid/wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

code-analysisctfeducation+7
152 months ago
CVE-2025-1094-PoC-Postgre-SQLi preview

CVE-2025-1094-PoC-Postgre-SQLi

GitHubishwardeepp/cve-2025-1094-poc-postgre-sqli

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

code-analysisdatabase-securityeducation+5
61 year ago
apache__dolphinscheduler_CVE-2022-34662_2-0-9 preview

apache__dolphinscheduler_CVE-2022-34662_2-0-9

GitHubshoucheng3/apache__dolphinscheduler_cve-2022-34662_2-0-9

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

cloud-securitycode-analysisexploitation+3
1 year ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubnollium/cve-2024-9264

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

code-analysisexploitationpayload-generation+4
1311 year ago
Previous123456Next