Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
294 results
CVE-2025-26794-exploit preview

CVE-2025-26794-exploit

GitHubxploitgh0st/cve-2025-26794-exploit

SQL injection exploit for CVE-2025-26794 in Exim 4.98. Automated data extraction via time-based blind SQLi. For authorized penetration testing only.

database-securityexploitationinformation-gathering+3
2
10 months ago
cve-2016-6662 preview

cve-2016-6662

GitHubboompig/cve-2016-6662

Exploit code for MySQL remote root code execution and privilege escalation (CVE-2016-6662), including Python and C implementations.

database-securityexploitationpayload-development+3
19 years ago
CVE-2025-67644-LangGraph-3.0.1-SQLite-Checkpoint-SQL-Injection preview

CVE-2025-67644-LangGraph-3.0.1-SQLite-Checkpoint-SQL-Injection

GitHubmbanyamer/cve-2025-67644-langgraph-3.0.1-sqlite-checkpoint-sql-injection

Proof-of-concept exploit for CVE-2025-67644, a SQL injection vulnerability in LangGraph SQLite Checkpoint. Demonstrates arbitrary SQL injection via…

database-securityeducationexploitation+4
16 months ago
postgres-bruteforcer preview

postgres-bruteforcer

GitHubrandomrobbiebf/postgres-bruteforcer

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

authenticationdatabase-securityexploitation+2
3 years ago
CVE-2024-57521-SQL-Injection-PoC preview

CVE-2024-57521-SQL-Injection-PoC

GitHubmrlihd/cve-2024-57521-sql-injection-poc

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

database-securityexploitationpayload-generation+3
8 months ago
CVE-2026-7229-SQLI preview

CVE-2026-7229-SQLI

GitHubxmyronn/cve-2026-7229-sqli

Proof of concept for authenticated SQL injection in Coaching Management System, demonstrating database dump via unsanitized complaintreply parameter.

database-securityexploitationpenetration-testing+3
4 months ago
CVE-2025-10046 preview
Archived

CVE-2025-10046

GitHubbytereaper77/cve-2025-10046

exploit SQL injection ELEX WooCommerce Google Shopping

database-securityexploitationpenetration-testing+3
611 months ago
ghauri preview

ghauri

GitHubr0oth3x49/ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

database-securitypenetration-testingvulnerability-scanners+2
4.1k10 months ago
mssqlbof preview

mssqlbof

GitHubmazx0p/mssqlbof

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

authenticationcommand-and-controldatabase-security+8
1004 months ago
cygor preview

cygor

GitHubtjnull/cygor

An modular asset discovery framework written in python to automate the repeating manual work

database-securitydns-analysisinformation-gathering+7
882 months ago
ODBParser preview

ODBParser

GitHubcitcheese/odbparser

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

database-securitydata-exfiltrationinformation-gathering+2
476 years ago
mongobleed-exploit-CVE-2025-14847 preview

mongobleed-exploit-CVE-2025-14847

GitHubsecurity-phoenix-demo/mongobleed-exploit-cve-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

code-analysisdatabase-securityeducation+3
137 months ago
CVE-2025-26794 preview

CVE-2025-26794

GitHuboscarbataille/cve-2025-26794

CVE-2025-26794: Blind SQL injection in Exim 4.98 (SQLite DBM)- exploit writeup

database-securityeducationexploitation+4
141 year ago
CVE-2021-3262 preview

CVE-2021-3262

GitHubl0lsec/cve-2021-3262

CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads,…

database-securityeducationexploitation+4
1 month ago
CVE-2026-52887-NocoBase-SQLi-RCE preview

CVE-2026-52887-NocoBase-SQLi-RCE

GitHubbiitts/cve-2026-52887-nocobase-sqli-rce

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

code-analysisdatabase-securityexploitation+4
24 days ago
CVE-2024-1071 preview

CVE-2024-1071

GitHubgbrsh/cve-2024-1071

Ultimate Member Unauthorized Database Access / SQLi

database-securityeducationexploitation+2
82 years ago
e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout preview

e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

GitHubhunt-benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

database-securityeducationexploitation+4
220 days ago
CVE-2025-1094-PoC-Postgre-SQLi preview

CVE-2025-1094-PoC-Postgre-SQLi

GitHubishwardeepp/cve-2025-1094-poc-postgre-sqli

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

code-analysisdatabase-securityeducation+5
61 year ago
Previous1…678…17Next