Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
614 results
Complete-google-dorks preview

Complete-google-dorks

GitHubnu11secur1ty/complete-google-dorks

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

database-securitydns-subdomain-enumerationexploitation+7
12
1 year ago
mongobleed-exploit-CVE-2025-14847 preview

mongobleed-exploit-CVE-2025-14847

GitHubsecurity-phoenix-demo/mongobleed-exploit-cve-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

code-analysisdatabase-securityeducation+3
138 months ago
CVE-2017-12635 preview

CVE-2017-12635

GitHubassalielmehdi/cve-2017-12635

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

database-securityeducationexploitation+4
106 years ago
Solr-GRAB preview

Solr-GRAB

GitHubgnosticplayers/solr-grab

Steal Apache Solr instance Queries with or without a username and password.

database-securityinformation-gatheringosint+1
125 years ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
13 days ago
CVE-2025-1094-PoC-Postgre-SQLi preview

CVE-2025-1094-PoC-Postgre-SQLi

GitHubishwardeepp/cve-2025-1094-poc-postgre-sqli

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

code-analysisdatabase-securityeducation+5
61 year ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
222 days ago
duckdb preview

duckdb

GitHubjepsen-io/duckdb

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

anomaly-detectiondatabase-securityeducation+2
55 months ago
CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated preview

CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated

GitHubh4md153v63n/cve-2022-40032_simple-task-managing-system-v1.0-sql-injection-vulnerability-unauthenticated

CVE-2022-40032: Simple Task Managing System - 'login' and 'password' SQL Injection (Unauthenticated)

database-securityexploitationpassword-attacks+3
52 years ago
CVE-2023-48084-Revised preview

CVE-2023-48084-Revised

GitHubmetthk/cve-2023-48084-revised

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

database-securityexploitationinformation-gathering+4
23 days ago
phpMyAdmin-CVE-2020-5504-Exploit preview

phpMyAdmin-CVE-2020-5504-Exploit

GitHubcerberusmrxi/phpmyadmin-cve-2020-5504-exploit

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

database-securityexploitationinformation-gathering+5
11 days ago
CVE-2026-2005 preview

CVE-2026-2005

GitHubopen-flaw/cve-2026-2005

PostgreSQL pgcrypto heap buffer overflow PoC demonstrating CVE-2026-2005: low-privileged RCE and privilege escalation to superuser via crafted…

binary-analysisbinary-exploitationdatabase-security+4
13 days ago
CVE-2026-69083_exploit preview

CVE-2026-69083_exploit

GitHub0xdak/cve-2026-69083_exploit

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

database-securitydata-exfiltrationexploitation+2
1 month ago
CVE-2026-39113 preview

CVE-2026-39113

GitHub20000419/cve-2026-39113

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

binary-exploitationcode-analysisdatabase-security+2
13 days ago
CVE-2024-51482-POC preview

CVE-2024-51482-POC

GitHub0xdaeras/cve-2024-51482-poc

Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.

database-securityeducationexploitation+4
73 months ago
CVE-2026-14669 preview

CVE-2026-14669

GitHubhackspeak/cve-2026-14669

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

binary-exploitationdatabase-securityexploitation+4
216 days ago
patch-CVE-2026-03200 preview

patch-CVE-2026-03200

GitHubgduma-phdata/patch-cve-2026-03200

Deployed patch for CVE-2026-03200, a critical SQL injection vulnerability in Progress MOVEit, with validation and deployment details.

database-securityvulnerability-analysis
11 days ago
mongobleed-scanner preview

mongobleed-scanner

GitHubpedrocruz2202/mongobleed-scanner

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

database-securityexploitationinformation-gathering+3
1 day ago
Previous1…456…35Next