Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
2
17 days ago
CVE-2023-25157-GeoServer-SQLi-Lab preview

CVE-2023-25157-GeoServer-SQLi-Lab

GitHubgiangdurian/cve-2023-25157-geoserver-sqli-lab

Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

database-securityeducationlabs-practice+3
1 month ago
CVE-2012-2122 preview

CVE-2012-2122

GitHubk3ystr0k3r/cve-2012-2122

CVE-2012-2122 - MySQL Authentication Bypass

authenticationdatabase-securityeducation+4
1 month ago
CVE-2026-36826 preview

CVE-2026-36826

GitHubforklit/cve-2026-36826

genesisQL-sqli-CVE-2026-36826

authenticationdatabase-securityexploitation+2
2 months ago
pharmacy-sqli-CVE-2026-7392 preview

pharmacy-sqli-CVE-2026-7392

GitHubmicrowaveabi/pharmacy-sqli-cve-2026-7392

SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection

database-securityeducationexploitation+3
3 months ago
CVE-2026-9082 preview

CVE-2026-9082

GitHubstrobelpierre/cve-2026-9082

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

database-securityinformation-gatheringreconnaissance+3
3 months ago
bouncer-overflow preview

bouncer-overflow

GitHubnicolasjulian/bouncer-overflow

Working POC of CVE-2026-6664 written by Sonnet 4.6

binary-exploitationdatabase-securityeducation+3
3 months ago
CVE-2026-3494_Verfication preview

CVE-2026-3494_Verfication

GitHubkelnor/cve-2026-3494_verfication

Reproduces and analyzes CVE-2026-3494, an audit logging bypass in MariaDB server_audit plugin, using Docker-based multi-version testing to compare…

database-securityeducationexploitation+2
3 months ago
CVE-2018-1058 preview

CVE-2018-1058

GitHubccchme/cve-2018-1058

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

database-securityeducationexploitation+3
3 months ago
vicidial-cve-2024-8503-blind-sqli-poc preview

vicidial-cve-2024-8503-blind-sqli-poc

GitHubmachine-farmer/vicidial-cve-2024-8503-blind-sqli-poc

Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.

database-securityeducationexploitation+3
4 months ago
CVE-2025-69214 preview

CVE-2025-69214

GitHublukasz-rybak/cve-2025-69214

Proof-of-concept for CVE-2025-69214: SQL injection in OpenSTAManager's ajax_select.php componenti endpoint. Includes vulnerable code analysis,…

database-securityeducationexploitation+3
4 months ago
CVE-2025-68400 preview

CVE-2025-68400

GitHublukasz-rybak/cve-2025-68400

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

database-securityeducationexploitation+3
4 months ago
CVE-2019-9193-Postgresql-RCE preview

CVE-2019-9193-Postgresql-RCE

GitHubcybersrmutl/cve-2019-9193-postgresql-rce

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

command-and-controldatabase-securityexploitation+2
7 months ago
CVE-2024-8465-PoC preview

CVE-2024-8465-PoC

GitHubsholls000/cve-2024-8465-poc

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

authenticationdatabase-securityeducation+3
7 months ago
CVE-2025-67261 preview

CVE-2025-67261

GitHubsmarttfoxx/cve-2025-67261

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the…

database-securityexploitationpenetration-testing+2
17 months ago
pedrocruz2202.github.io preview

pedrocruz2202.github.io

GitHubpedrocruz2202/pedrocruz2202.github.io

🛡️ Detect vulnerable MongoDB instances with the high-performance MongoBleed scanner for CVE-2025-14847, ensuring network security and data…

database-securityexploitationnetwork-security+2
7 months ago
CVE-2025-14847_Expolit preview

CVE-2025-14847_Expolit

GitHubalexcyberx/cve-2025-14847_expolit

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

database-securitydata-exfiltrationexploitation+4
27 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubsahar042/cve-2025-14847

Proof-of-concept exploit for CVE-2025-14847, a MongoDB bleed vulnerability. Enables verification of vulnerable instances and understanding of attack…

database-securityeducationexploitation+2
7 months ago
Previous123Next