Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
375 results
redis-stack-CVE-2024-55656 preview

redis-stack-CVE-2024-55656

GitHubrick2600/redis-stack-cve-2024-55656
binary-exploitationdatabase-securityexploitation+3
1 year ago
cve-2021-29442-Nacos-Derby-rce-exp preview

cve-2021-29442-Nacos-Derby-rce-exp

GitHubnanaao/cve-2021-29442-nacos-derby-rce-exp

Nacos Derby命令执行漏洞利用脚本

command-and-controldatabase-securityexploitation+3
1 year ago
odat preview

odat

GitHubquentinhardy/odat

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

command-and-controldatabase-securityexploitation+4
1.8k4 months ago
firebaseExploiter preview

firebaseExploiter

GitHubsecurebinary/firebaseexploiter

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

database-securityexploitationpenetration-testing+2
1753 years ago
Cisco-UCM-SQLi-Scripts preview

Cisco-UCM-SQLi-Scripts

GitHubfsecurelabs/cisco-ucm-sqli-scripts

Scripts that can be used to exploit CVE-2019-15972 which was an Authenticated SQLi issue in Cisco Unified Call Manager (UCM).

database-securityexploitationpenetration-testing+2
76 years ago
refreshing-mcp-tool preview

refreshing-mcp-tool

GitHubrbowes-r7/refreshing-mcp-tool

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

database-securityexploitationinformation-gathering+5
73 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubsakthivel10q/cve-2025-14847

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…

database-securityexploitationinformation-gathering+3
12 days ago
CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework preview

CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework

GitHubcerberusmrxi/cve-2026-44680-mikroorm-sql-injection-exploit-framework

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

code-analysisdatabase-securityexploitation+3
11 month ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubmr-r00t11/cve-2024-4879

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

database-securityexploitationinformation-gathering+3
42 years ago
o5logon-fetch preview

o5logon-fetch

GitHubhantwister/o5logon-fetch

Attempts to exploit CVE-2012-3137 on vulnerable Oracle servers

database-securityexploitationpassword-cracking+2
312 years ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
CVE-2025-70829 preview

CVE-2025-70829

GitHubxiaoxiaoranxxx/cve-2025-70829

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

authenticationdatabase-securityexploitation+3
46 months ago
CVE-2025-70828 preview

CVE-2025-70828

GitHubxiaoxiaoranxxx/cve-2025-70828

Datart v1.0.0-rc.3 JDBC Connection String Injection Leading to Arbitrary File Read

database-securityexploitationinformation-gathering+3
46 months ago
CVE-2023-50071 preview

CVE-2023-50071

GitHubgeraldoalcantara/cve-2023-50071

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department in Customer Support System 1.0 allow authenticated…

code-analysisdatabase-securityexploitation+3
32 years ago
CVE-2010-3600-PythonHackOracle11gR2 preview

CVE-2010-3600-PythonHackOracle11gR2

GitHublaitrungminhduc/cve-2010-3600-pythonhackoracle11gr2

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

database-securityexploitationpenetration-testing+1
28 years ago
CVE-2024-1346 preview

CVE-2024-1346

GitHubpetergabaldon/cve-2024-1346

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

binary-analysisdatabase-securityexploitation+3
22 years ago
CVE-2025-6713 preview

CVE-2025-6713

GitHubc137req/cve-2025-6713

craft aggregation pipeline to access data without proper authorisation due to improper handling of $mergeCursors in MongoDB >v8.0 <8.0.7, >v7.0…

database-securityexploitationpenetration-testing+2
15 months ago
sakthivel10q.github.io preview

sakthivel10q.github.io

GitHubsakthivel10q/sakthivel10q.github.io

🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.

database-securityexploitationinformation-gathering+2
6 months ago
Previous1234…21Next