Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
197 results
mongobleed-exploit-CVE-2025-14847 preview

mongobleed-exploit-CVE-2025-14847

GitHubsecurity-phoenix-demo/mongobleed-exploit-cve-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

code-analysisdatabase-securityeducation+3
137 months ago
Solr-GRAB preview

Solr-GRAB

GitHubgnosticplayers/solr-grab

Steal Apache Solr instance Queries with or without a username and password.

database-securityinformation-gatheringosint+1
125 years ago
mongobleed-scanner preview

mongobleed-scanner

GitHubpedrocruz2202/mongobleed-scanner

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

database-securityexploitationinformation-gathering+3
2 days ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
28 days ago
CVE-2026-14762-PoC-Exploit preview

CVE-2026-14762-PoC-Exploit

GitHubtc4dy/cve-2026-14762-poc-exploit

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

command-and-controldatabase-securityexploitation+7
21 month ago
Discuz-X5.0-Authentication-Bypass-Exploit-Framework preview

Discuz-X5.0-Authentication-Bypass-Exploit-Framework

GitHubcerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

authentication-authorizationdatabase-securityexploit-frameworks+4
127 days ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubmr-r00t11/cve-2024-4879

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

database-securityexploitationinformation-gathering+3
42 years ago
CVE-2022-40347_Intern-Record-System-phone-V1.0-SQL-Injection-Vulnerability-Unauthenticated preview

CVE-2022-40347_Intern-Record-System-phone-V1.0-SQL-Injection-Vulnerability-Unauthenticated

GitHubh4md153v63n/cve-2022-40347_intern-record-system-phone-v1.0-sql-injection-vulnerability-unauthenticated

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)

database-securityexploitationinformation-gathering+3
3
CVE-2026-9082 preview

CVE-2026-9082

GitHubstrobelpierre/cve-2026-9082

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

database-securityinformation-gatheringreconnaissance+3
2 months ago
CVE-2019-20933 preview

CVE-2019-20933

GitHubdungsocool/cve-2019-20933

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

authentication-authorizationctfdatabase-security+5
2 months ago
CVE-2024-46636-SQLi-MODAPS preview

CVE-2024-46636-SQLi-MODAPS

GitHubnu1l0/cve-2024-46636-sqli-modaps

SQL Injection vulnerability in NASA EOSDIS MODAPS due to improper input validation in the `category` parameter. This flaw allows attackers to…

database-securityinformation-gatheringpenetration-testing+2
24 months ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
26 months ago
vicidial-cve-2024-8503-blind-sqli-poc preview

vicidial-cve-2024-8503-blind-sqli-poc

GitHubmachine-farmer/vicidial-cve-2024-8503-blind-sqli-poc

Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.

database-securityeducationexploitation+3
3 months ago
CVE-2021-42667 preview

CVE-2021-42667

GitHub0xdeku/cve-2021-42667

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

database-securityexploitationinformation-gathering+3
24 years ago
CVE-2025-65354 preview

CVE-2025-65354

GitHubamaansiddd787/cve-2025-65354

Public disclosure and technical details for CVE-2025-65354 (SQL Injection)

database-securityeducationinformation-gathering+3
18 months ago
CVE-2025-64513 preview

CVE-2025-64513

GitHubshinyseam/cve-2025-64513

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

authenticationdatabase-securityexploitation+3
19 months ago
mongobleed preview

mongobleed

GitHubadolfbharath/mongobleed

CVE-2025-14847 explaination and lab

cryptographydatabase-securityeducation+3
17 months ago
CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 preview

CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026

GitHub14mb1v45h/cyberdudebivash-mongodb-detector-v2026

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

database-securityexploitationinformation-gathering+3
7 months ago
Previous1234…11Next
2 years ago