Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
xolo preview

xolo

GitHubetlownoise/xolo

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

database-securityinformation-gatheringpenetration-testing
195 years ago
OracleOTM preview

OracleOTM

GitHubofirhamam/oracleotm

Python tool for exploiting CVE-2021-35616

database-securityexploitationinformation-gathering+3
114 years ago
CVE-2019-9193 preview

CVE-2019-9193

GitHubgeniuszly/cve-2019-9193

is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)

database-securityeducationexploitation+3
41 year ago
drupal-jsonapi-sqli-scanner preview

drupal-jsonapi-sqli-scanner

GitHubridhinva/drupal-jsonapi-sqli-scanner

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

database-securitydata-exfiltrationexploitation+5
21 month ago
CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework preview

CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework

GitHubcerberusmrxi/cve-2026-44680-mikroorm-sql-injection-exploit-framework

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

code-analysisdatabase-securityexploitation+3
11 month ago
mongobleed preview

mongobleed

GitHubnma-io/mongobleed

golang test tool for mongobleed (cve-2025-14847)

database-securityexploitationpenetration-testing+2
28 months ago
HQLmap preview
Archived

HQLmap

GitHubpaulsec/hqlmap

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

database-securityinformation-gatheringpenetration-testing+2
2286 years ago
EDRaser preview

EDRaser

GitHubsafebreach-labs/edraser

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

database-securitypost-exploitation
3752 years ago
solarflare preview

solarflare

GitHubmubix/solarflare

SolarWinds Orion Account Audit / Password Dumping Utility

database-securityencryption-decryption-toolspassword-cracking+1
3522 years ago
wodat preview

wodat

GitHubinitroot/wodat

Windows Oracle Database Attack Toolkit

database-securitypassword-attackspenetration-testing+1
794 years ago
CVE-2026-60137 preview

CVE-2026-60137

GitHubadarshthakur14777-cyber/cve-2026-60137

wpsqli full SQLi extractor + dumper for CVE-2026-60137

database-securityexploitationinformation-gathering+5
1 month ago
CVE-2023-48084-Revised preview

CVE-2023-48084-Revised

GitHubmetthk/cve-2023-48084-revised

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

database-securityexploitationinformation-gathering+4
1 month ago
CVE-2023-48084 preview

CVE-2023-48084

GitHubhamibubu/cve-2023-48084

Python program to dump all the databases, exploiting NagiosXI sqli vulnerability

database-securityexploitationpenetration-testing+2
12 years ago
SSCMS_Decrypt preview

SSCMS_Decrypt

GitHubjas502n/sscms_decrypt

sscms database decrypt

database-securityencryption-decryption-toolspassword-cracking+2
104 years ago
CVE-2019-9193 preview

CVE-2019-9193

GitHubpaulotrindadec/cve-2019-9193

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

database-securityexploitationpenetration-testing+2
13 years ago
cve-2021-29442-Nacos-Derby-rce-exp preview

cve-2021-29442-Nacos-Derby-rce-exp

GitHubnanaao/cve-2021-29442-nacos-derby-rce-exp

Nacos Derby命令执行漏洞利用脚本

command-and-controldatabase-securityexploitation+3
1 year ago
Previous123Next