Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
362 results
PySQLRecon preview

PySQLRecon

GitHubtw1sm/pysqlrecon

Offensive MSSQL toolkit written in Python, based off SQLRecon

command-and-controldatabase-securityexploitation+3
212
4 months ago
CVE-2026-26980-PoC preview

CVE-2026-26980-PoC

GitHubn0bitaemon/cve-2026-26980-poc

Ghost CMS Content API Blind SQL Injection

database-securityexploitationinformation-gathering+4
12 months ago
CVE-2023-38891 preview

CVE-2023-38891

GitHubjselliott/cve-2023-38891

Authenticated SQL Injection Vulnerability in VTiger Open Source CRM v7.5

database-securityexploitationpenetration-testing+2
13 years ago
CVE-2025-22953 preview

CVE-2025-22953

GitHubmaliktawfiq/cve-2025-22953

EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953

database-securityexploitationinformation-gathering+3
21 year ago
CVE-2023-49968 preview

CVE-2023-49968

GitHubgeraldoalcantara/cve-2023-49968

Customer Support System 1.0 - SQL Injection Vulnerability in manage_department.php via "id" URL Parameter

database-securityexploitationinformation-gathering+3
2 years ago
CVE-2023-49969 preview

CVE-2023-49969

GitHubgeraldoalcantara/cve-2023-49969

Customer Support System 1.0 - SQL Injection Vulnerability in edit_customer via "id" URL Parameter

database-securityexploitationpenetration-testing+2
2 years ago
cve-2025-14847 preview

cve-2025-14847

GitHubkuyrathdaro/cve-2025-14847

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

database-securityeducationexploitation+3
8 months ago
CVE-2022-22980 preview

CVE-2022-22980

GitHubtrganda/cve-2022-22980

Proof-of-concept exploit for CVE-2022-22980 targeting Spring Data MongoDB. Demonstrates remote code execution via crafted MongoDB queries. Requires…

database-securityexploitationvulnerability-analysis+1
324 years ago
LabS4U2Self preview

LabS4U2Self

GitHubotterhacker/labs4u2self

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

authentication-authorizationdatabase-securityeducation+5
313 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubjoshuavanderpoll/cve-2025-14847

CVE-2025-14847 (MongoBleed)

database-securityexploitationinformation-gathering+3
48 months ago
MongoBleed-CVE-2025-14847 preview

MongoBleed-CVE-2025-14847

GitHubsystemhaus-schulz/mongobleed-cve-2025-14847

MongoBleed CVE-2025-14847 Vulnerability Checker

database-securityexploitationinformation-gathering+3
8 months ago
CVE-2022-37203 preview

CVE-2022-37203

GitHubagainstthelight/cve-2022-37203

CVE-2022-37203 POC

database-securityexploitationpenetration-testing+2
4 years ago
CVE-2022-37206 preview

CVE-2022-37206

GitHubagainstthelight/cve-2022-37206

CVE-2022-37206 POC

database-securityexploitationpenetration-testing+2
4 years ago
dashbuilder preview

dashbuilder

GitHubshanika04/dashbuilder

CVE-2016-4999

database-securitygeneral-purpose-utilitieslog-analysis+3
5 years ago
CVE-2025-45809-PoC preview

CVE-2025-45809-PoC

GitHublearner202649/cve-2025-45809-poc

Time-based blind SQL injection proof-of-concept for LiteLLM v1.65.4. Exploits the `/key/block` endpoint to extract database contents and read server…

api-security-testingdatabase-securityeducation+3
3 months ago
CVE-2023-49954.github.io preview

CVE-2023-49954.github.io

GitHubcve-2023-49954/cve-2023-49954.github.io

SQL Injection in 3CX CRM Integration

api-security-testingdatabase-securityinformation-gathering+3
22 years ago
CVE-2024-48427 preview

CVE-2024-48427

GitHubvighneshnair7/cve-2024-48427

Proof-of-concept for CVE-2024-48427: SQL injection in Sourcecodester Packers and Movers Management System v1.0. Exploits the id parameter to execute…

database-securityexploitationinformation-gathering+3
11 year ago
cve-search preview

cve-search

GitHubcve-search/cve-search

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

database-securityinformation-gatheringioc-management+4
2.6k13 days ago
Previous1…456…21Next