Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
CVE-2026-33917_SqlInjectionVulnerabilityOpenEMR8.0.0 preview

CVE-2026-33917_SqlInjectionVulnerabilityOpenEMR8.0.0

GitHubchrissub08/cve-2026-33917_sqlinjectionvulnerabilityopenemr8.0.0

Proof-of-concept exploit for CVE-2026-33917, a SQL injection vulnerability in OpenEMR <8.0.0.3. Includes technical analysis, vulnerable code paths,…

database-securityeducationexploitation+3
5 months ago
ADEL preview

ADEL

GitHubmspreitz/adel

Forensic tool to extract and analyze SQLite databases from rooted Android devices, generating structured XML reports for digital investigations.

android-securitydatabase-securitydata-recovery+4
13011 years ago
OracleOTM preview

OracleOTM

GitHubofirhamam/oracleotm

Python tool for exploiting CVE-2021-35616

database-securityexploitationinformation-gathering+3
114 years ago
MongoBLEED---CVE-2025-14847-POC- preview

MongoBLEED---CVE-2025-14847-POC-

GitHubnonameerror/mongobleed---cve-2025-14847-poc-

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

database-securityexploitationfuzzing+3
17 months ago
CVE-2024-34693 preview

CVE-2024-34693

GitHubmr-r00t11/cve-2024-34693

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

database-securitydata-exfiltrationexploitation+3
2 years ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubmr-r00t11/cve-2024-4879

Python script to detect CVE-2024-4879 in ServiceNow instances and extract database connection details including credentials for security assessment.

database-securityexploitationinformation-gathering+3
42 years ago
CVE-2025-69215 preview

CVE-2025-69215

GitHublukasz-rybak/cve-2025-69215

Proof-of-concept exploit and technical analysis for an authenticated SQL injection vulnerability in OpenSTAManager's Stampe module, including a full…

database-securityeducationexploitation+3
4 months ago
H2-database-CVE-2022-23221 preview

H2-database-CVE-2022-23221

GitHubstraightsang/h2-database-cve-2022-23221

Reproduces CVE-2022-23221 RCE in H2 database via malicious JDBC URL with INIT parameter, using Docker-based lab environment and Python PoC exploit…

database-securityeducationexploitation+3
1 month ago
CVE-2019-9193-Postgresql-RCE preview

CVE-2019-9193-Postgresql-RCE

GitHubcybersrmutl/cve-2019-9193-postgresql-rce

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

command-and-controldatabase-securityexploitation+2
7 months ago
CVE-2010-3600-PythonHackOracle11gR2 preview

CVE-2010-3600-PythonHackOracle11gR2

GitHublaitrungminhduc/cve-2010-3600-pythonhackoracle11gr2

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

database-securityexploitationpenetration-testing+1
28 years ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubjdusane/cve-2024-4879

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

database-securityexploitationinformation-gathering+3
2 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubjoshuavanderpoll/cve-2025-14847

Exploit script for CVE-2025-14847 (MongoBleed) that triggers heap memory disclosure in MongoDB by sending crafted OP_MSG packets, leaking sensitive…

database-securityexploitationinformation-gathering+3
47 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit preview

CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit

GitHubt0x1cx/cve-2021-36396-moodle-time-based-sqli-exploit

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

database-securityeducationexploitation+3
222 years ago