Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
cve-2022-22976-bcrypt-skips-salt preview

cve-2022-22976-bcrypt-skips-salt

GitHubspring-io/cve-2022-22976-bcrypt-skips-salt

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

authenticationdatabase-securityencryption-decryption-tools+3
1
4 years ago
CVE-2025-67261 preview

CVE-2025-67261

GitHubsmarttfoxx/cve-2025-67261

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the…

database-securityexploitationpenetration-testing+2
17 months ago
CVE-2021-42668 preview

CVE-2021-42668

GitHub0xdeku/cve-2021-42668

Proof-of-concept exploit for CVE-2021-42668, a SQL injection in Engineers Online Portal. Uses the vulnerable id parameter in my_classmates.php to…

database-securityexploitationpenetration-testing+2
14 years ago
CVE-2025-28346 preview

CVE-2025-28346

GitHubshubham03007/cve-2025-28346

Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter

database-securityexploitationpenetration-testing+2
11 year ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubsahar042/cve-2025-14847

Proof-of-concept exploit for CVE-2025-14847, a MongoDB bleed vulnerability. Enables verification of vulnerable instances and understanding of attack…

database-securityeducationexploitation+2
7 months ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
ctf-cve-2019-11043 preview

ctf-cve-2019-11043

GitHuba1ex-var1amov/ctf-cve-2019-11043

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

cloud-securitycontainer-securityctf+8
1 year ago
CVE-2024-8465-PoC preview

CVE-2024-8465-PoC

GitHubsholls000/cve-2024-8465-poc

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

authenticationdatabase-securityeducation+3
7 months ago
CVE-2025-11391 preview

CVE-2025-11391

GitHubmoritakaaz/cve-2025-11391

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

database-securityeducationexploitation+4
10 months ago
CVE-2019-9193-Postgresql-RCE preview

CVE-2019-9193-Postgresql-RCE

GitHubcybersrmutl/cve-2019-9193-postgresql-rce

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

command-and-controldatabase-securityexploitation+2
7 months ago
pedrocruz2202.github.io preview

pedrocruz2202.github.io

GitHubpedrocruz2202/pedrocruz2202.github.io

🛡️ Detect vulnerable MongoDB instances with the high-performance MongoBleed scanner for CVE-2025-14847, ensuring network security and data…

database-securityexploitationnetwork-security+2
7 months ago
MongoBleed-exploit preview

MongoBleed-exploit

GitHubeljoamy/mongobleed-exploit

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

ctfdatabase-securityeducation+5
7 months ago
CVE-2024-57430 preview

CVE-2024-57430

GitHubahrixia/cve-2024-57430

CVE-2024-57430: PHPJabbers Cinema Booking System v2.0 is vulnerable to SQL injection, leading to unauthorized data access and privilege escalation.

database-securityexploitationinformation-gathering+3
1 year ago
CVE-2023-43144 preview

CVE-2023-43144

GitHubpegasus0xx/cve-2023-43144

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

code-analysisdatabase-securityexploitation+2
2 years ago
CVE-2025-28009 preview

CVE-2025-28009

GitHub0xs4h4/cve-2025-28009

SQL Injection in Dietiqa App v1.0.20 (CVE-2025-28009) – Unauthenticated remote data access via vulnerable parameter.

database-securityeducationexploitation+2
1 year ago
CVE-2026-3494_Verfication preview

CVE-2026-3494_Verfication

GitHubkelnor/cve-2026-3494_verfication

Reproduces and analyzes CVE-2026-3494, an audit logging bypass in MariaDB server_audit plugin, using Docker-based multi-version testing to compare…

database-securityeducationexploitation+2
3 months ago
Gopherus preview

Gopherus

GitHubtarunkant/gopherus

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

database-securityexploitationpayload-generation+3
3.4k3 years ago
CVE-2019-9193 preview

CVE-2019-9193

GitHubb4kesn4ke/cve-2019-9193

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

database-securityexploitationpayload-development+3
214 years ago
Previous123Next