Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
115 results
chusa preview

chusa

GitHubnu11secur1ty/chusa

chusa - 注射 - the new generation of sqlmap

database-securityexploitationinformation-gathering+3
39 months ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
38 months ago
CVE-2019-20933 preview

CVE-2019-20933

GitHubhydragyrum/cve-2019-20933

Proof-of-concept exploit client for InfluxDB authentication bypass (CVE-2019-20933). Executes arbitrary queries against vulnerable InfluxDB instances…

authentication-authorizationdatabase-securityexploitation+2
25 years ago
CVE-2026-69084-PoC preview

CVE-2026-69084-PoC

GitHubboreas37/cve-2026-69084-poc

CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

database-securityexploitationpenetration-testing+3
11 month ago
CVE-2021-27928-POC preview

CVE-2021-27928-POC

GitHubshamo0/cve-2021-27928-poc

CVE-2021-27928-POC

database-securityexploitationpayload-generation+3
14 years ago
ansible-mysql-cve-2016-6662 preview

ansible-mysql-cve-2016-6662

GitHubmeersjo/ansible-mysql-cve-2016-6662

Simple ansible playbook to patch mysql servers against CVE-2016-6662

configuration-auditingdatabase-securitydevsecops+3
110 years ago
CVE-2022-28346 preview

CVE-2022-28346

GitHubkamal-marouane/cve-2022-28346

A flaw was found in the Django package, which leads to a SQL injection. This flaw allows an attacker using a crafted dictionary containing malicious…

database-securityeducationexploitation+3
12 years ago
bouncer-overflow preview

bouncer-overflow

GitHubnicolasjulian/bouncer-overflow

Working POC of CVE-2026-6664 written by Sonnet 4.6

binary-exploitationdatabase-securityeducation+3
4 months ago
Django-faille-CVE-2025-57833_test preview

Django-faille-CVE-2025-57833_test

GitHubloic-houchi/django-faille-cve-2025-57833_test

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

code-analysisdatabase-securityeducation+3
21 year ago
CVE-2024-36039_PoC preview

CVE-2024-36039_PoC

GitHubzenniskayy2k4/cve-2024-36039_poc

PoC for CVE-2024-36039: Demonstrating SQL Injection via PyMySQL Object-to-String serialization flaw

database-securityeducationexploitation+3
16 months ago
Mongobleed-Detector-CVE-2025-14847 preview

Mongobleed-Detector-CVE-2025-14847

GitHubkeraattin/mongobleed-detector-cve-2025-14847

Mongobleed Detector CVE-2025-14847

database-securityexploitationinformation-gathering+3
18 months ago
cve-2025-14847 preview

cve-2025-14847

GitHubkuyrathdaro/cve-2025-14847

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

database-securityeducationexploitation+3
8 months ago
CVE-2024-58290-Xhibiter-SQLi preview

CVE-2024-58290-Xhibiter-SQLi

GitHubsohelyousef/cve-2024-58290-xhibiter-sqli

Proof of Concept (PoC) for SQL Injection in Xhibiter NFT Marketplace 1.10.2 (Collections Endpoint). Discovered by Sohel Yousef.

database-securityexploitationinformation-gathering+3
8 months ago
CVE-2025-14847---MongoBleed preview

CVE-2025-14847---MongoBleed

GitHubsaereya/cve-2025-14847---mongobleed

Go proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a MongoDB memory disclosure vulnerability. Crafts malformed BSON documents to leak…

database-securityeducationexploitation+3
9 months ago
CVE-2025-11391 preview

CVE-2025-11391

GitHubmoritakaaz/cve-2025-11391

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

database-securityeducationexploitation+4
11 months ago
cve-2025-25257 preview

cve-2025-25257

GitHublytianahkone-boop/cve-2025-25257

Reproducible Docker lab for CVE-2025-25257, demonstrating SQL injection bypass and data exfiltration via HTTP Authorization header on a simulated…

database-securityeducationexploitation+3
9 months ago
Adminer-CVE-2021-43008 preview

Adminer-CVE-2021-43008

GitHubdaturasaturated/adminer-cve-2021-43008

Adminer CVE-2021-43008 PoC

database-securitydata-exfiltrationexploitation+3
6 months ago
CVE-2021-35042 preview

CVE-2021-35042

GitHubluuanhduc/cve-2021-35042

Django SQL injection vulnerability

database-securityeducationexploitation+3
3 years ago
Previous1234567Next