Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
PoC-CVE-2024-44349 preview

PoC-CVE-2024-44349

GitHubandreaf17/poc-cve-2024-44349

Proof-of-concept exploit for CVE-2024-44349, an SQL injection in Anteeo WMS v4.7.x, enabling database dumping and arbitrary SQL query execution.

ctfdatabase-securityeducation+4
1
10 months ago
CTF_Django_CVE-2022-34265 preview

CTF_Django_CVE-2022-34265

GitHublnwza0x0a/ctf_django_cve-2022-34265

Docker-based CTF challenge demonstrating SQL injection in Django's Trunc() and Extract() database functions (CVE-2022-34265) with UNION-based payload…

ctfdatabase-securityeducation+3
14 years ago
CTF_CVE-2020-7471 preview

CTF_CVE-2020-7471

GitHubtempuss/ctf_cve-2020-7471

CTF challenge exploiting CVE-2020-7471, a Django SQL injection vulnerability in PostgreSQL StringAgg, with Docker setup and exploit scripts.

ctfdatabase-securityeducation+4
5 years ago
vucsa preview

vucsa

GitHubwarxim/vucsa

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

binary-exploitationctfeducation+3
1033 years ago
CVE-2026-29782-OpenSTAManager-RCE preview

CVE-2026-29782-OpenSTAManager-RCE

GitHubhackerking24/cve-2026-29782-openstamanager-rce

Proof-of-concept exploit for CVE-2026-29782, chaining SQL injection and PHP object injection to achieve remote code execution in OpenSTAManager.…

ctfeducationexploitation+2
27 days ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
22 days ago
Zero-Day-Legacy preview

Zero-Day-Legacy

GitHubayham-megdadi/zero-day-legacy

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

ctfeducationlabs-practice+6
23 months ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubgiangdurian/cve-2026-63030-cve-2026-60137

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

ctfeducationexploitation+4
2 months ago
EXPLOIT-CVE-2026-63030 preview

EXPLOIT-CVE-2026-63030

GitHubjoaovicdev/exploit-cve-2026-63030

Docker-based vulnerable WordPress lab with Python exploit demonstrating pre-auth route confusion and SQL injection chain (CVE-2026-63030 +…

ctfeducationexploitation+3
12 months ago
CVE-2017-8917-Joomla preview

CVE-2017-8917-Joomla

GitHubbaptistecontreras/cve-2017-8917-joomla

CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit

ctfeducationexploitation+3
22 years ago
EverShop-Lab-CVE-2026-25993 preview

EverShop-Lab-CVE-2026-25993

GitHubmoxitpanchal/evershop-lab-cve-2026-25993

Docker-based lab for exploiting CVE-2026-25993, a second-order SQL injection in EverShop. Deploy, enumerate, and dump the database via crafted…

ctfeducationlabs-practice+2
12 months ago
CVE-2025-8018 preview

CVE-2025-8018

GitHubdrackyjr/cve-2025-8018

Python PoC exploit for CVE-2025-8018, a critical unauthenticated SQL injection in Food Ordering Review System v1.0. Supports time-based blind and…

ctfeducationexploitation+3
21 year ago
joomla.3.7.0exploit preview

joomla.3.7.0exploit

GitHubztrxwzy/joomla.3.7.0exploit

Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data…

ctfexploitationpenetration-testing+2
27 months ago
cve-2026-6379 preview

cve-2026-6379

GitHubdinosn/cve-2026-6379

Docker-based lab kit for CVE-2026-6379, an unauthenticated SQL injection in WP Photo Album Plus. Includes time-based blind PoC, root-cause analysis,…

ctfeducationexploitation+5
5 months ago
CVE-2025-4396 preview

CVE-2025-4396

GitHubsup3rdav3/cve-2025-4396

CVE-2025-4396 - WordPress Relevanssi Time-Based Blind SQL Injection

ctfeducationexploitation+5
4 months ago
mysqli preview

mysqli

GitHubrgkue/mysqli

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

ctfeducationpassword-cracking+3
3 months ago
CVE-2026-4060-PoC preview

CVE-2026-4060-PoC

GitHubydking0911/cve-2026-4060-poc

Proof-of-concept for CVE-2026-4060: unauthenticated time-based blind SQL injection in Geo Mashup WordPress plugin via ORDER BY clause. Includes…

ctfeducationexploitation+3
4 months ago
poc_cve-2026-42208 preview

poc_cve-2026-42208

GitHubhaerin-l/poc_cve-2026-42208

Reproduction lab for CVE-2026-42208, a critical pre-authentication SQL injection in LiteLLM. Includes Docker-based vulnerable/patched environments,…

ctfeducationlabs-practice+3
4 months ago
Previous123Next