Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
CVE-2025-14847 preview

CVE-2025-14847

GitHubsakthivel10q/cve-2025-14847

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…

database-securityexploitationinformation-gathering+3
1
1 day ago
CVE-2025-59213 preview

CVE-2025-59213

GitHubsynacktiv/cve-2025-59213

Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

database-securityexploitationpenetration-testing+2
33 months ago
CVE-2026-34308 preview

CVE-2026-34308

GitHubjoakimbulow/cve-2026-34308

Proof-of-concept for CVE-2026-34308, a MySQL Server JSON component denial-of-service vulnerability. Demonstrates stack exhaustion via deep $ref…

database-securityexploitationpenetration-testing+1
4 months ago
CVE-2024-43468 preview

CVE-2024-43468

GitHubsynacktiv/cve-2024-43468

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

database-securityexploitationpenetration-testing+2
965 months ago
CVE-2019-9193-Postgresql-RCE preview

CVE-2019-9193-Postgresql-RCE

GitHubcybersrmutl/cve-2019-9193-postgresql-rce

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

command-and-controldatabase-securityexploitation+2
7 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
mongobleed-detector preview

mongobleed-detector

GitHubneo23x0/mongobleed-detector

Detection Script for MongoBleed Exploitation

database-securitydigital-forensicsforensics+5
818 months ago
MongoBLEED---CVE-2025-14847-POC- preview

MongoBLEED---CVE-2025-14847-POC-

GitHubnonameerror/mongobleed---cve-2025-14847-poc-

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

database-securityexploitationfuzzing+3
18 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubjoshuavanderpoll/cve-2025-14847

CVE-2025-14847 (MongoBleed)

database-securityexploitationinformation-gathering+3
48 months ago
CVE-2025-64513 preview

CVE-2025-64513

GitHubshinyseam/cve-2025-64513

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

authenticationdatabase-securityexploitation+3
110 months ago
CVE-2024-10140 preview

CVE-2024-10140

GitHubholypryx/cve-2024-10140

SQL injection exploit script targeting CVE-2024-10140 in the /php/manage_supplier.php endpoint, enabling arbitrary SQL command injection via the id…

database-securityexploitationpenetration-testing+2
21 year ago
CVE-2024-4879 preview

CVE-2024-4879

GitHub0xwhoami35/cve-2024-4879

Exploit script for ServiceNow CVE-2024-4879 that enables unauthenticated remote code execution, with mass target scanning and database dumping…

database-securityexploitationinformation-gathering+3
1 year ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubjdusane/cve-2024-4879

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

database-securityexploitationinformation-gathering+3
2 years ago
CVE-2024-34693 preview

CVE-2024-34693

GitHubmr-r00t11/cve-2024-34693

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

database-securitydata-exfiltrationexploitation+3
2 years ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubmr-r00t11/cve-2024-4879

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

database-securityexploitationinformation-gathering+3
42 years ago
CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit preview

CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit

GitHubt0x1cx/cve-2021-36396-moodle-time-based-sqli-exploit

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

database-securityeducationexploitation+3
222 years ago
CVE-2024-32640-SQLI-MuraCMS preview

CVE-2024-32640-SQLI-MuraCMS

GitHub0xyumeko/cve-2024-32640-sqli-muracms

Exploit script for CVE-2024-32640, an SQL injection vulnerability in Mura/Masa CMS, using ghauri to enumerate and dump database contents.

database-securityexploitationpenetration-testing+3
12 years ago
CVE-2023-20110 preview

CVE-2023-20110

GitHubredfr0g/cve-2023-20110

PoC script for CVE-2023-20110 - Cisco Smart Software Manager On-Prem SQL Injection Vulnerability

database-securityexploitationpenetration-testing+2
163 years ago
Previous12Next