Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
614 results
CVE-2024-10140 preview

CVE-2024-10140

GitHubholypryx/cve-2024-10140

SQL injection exploit script targeting CVE-2024-10140 in the /php/manage_supplier.php endpoint, enabling arbitrary SQL command injection via the id…

database-securityexploitationpenetration-testing+2
2
1 year ago
CVE-2025-68400 preview

CVE-2025-68400

GitHublukasz-rybak/cve-2025-68400

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

database-securityeducationexploitation+3
4 months ago
CVE-2025-69213 preview

CVE-2025-69213

GitHublukasz-rybak/cve-2025-69213

Proof-of-concept repository for CVE-2025-69213, demonstrating a SQL injection vulnerability in OpenSTAManager's ajax_complete.php endpoint with…

database-securityeducationexploitation+3
4 months ago
CVE-2025-65950 preview

CVE-2025-65950

GitHublukasz-rybak/cve-2025-65950

Proof-of-concept exploit for a critical time-based blind SQL injection vulnerability in WBCE CMS, enabling low-privileged users to execute arbitrary…

database-securityeducationexploitation+3
4 months ago
Django-faille-CVE-2025-57833_test preview

Django-faille-CVE-2025-57833_test

GitHubloic-houchi/django-faille-cve-2025-57833_test

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

code-analysisdatabase-securityeducation+3
211 months ago
pharmacy-sqli-CVE-2026-7392 preview

pharmacy-sqli-CVE-2026-7392

GitHubmicrowaveabi/pharmacy-sqli-cve-2026-7392

SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection

database-securityeducationexploitation+3
3 months ago
CVE-2025-14847_Expolit preview

CVE-2025-14847_Expolit

GitHubalexcyberx/cve-2025-14847_expolit

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

database-securitydata-exfiltrationexploitation+4
27 months ago
CVE-2025-46817-PoC preview

CVE-2025-46817-PoC

GitHubslayerkkkk/cve-2025-46817-poc

C-based exploit for CVE-2025-46817, a Redis integer overflow vulnerability, enabling crash detection and potential RCE via Lua unpack() payload.

database-securityexploitationfuzzing+2
210 months ago
MongoBleed preview

MongoBleed

GitHubsho-luv/mongobleed

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…

ctfdatabase-securityeducation+6
26 months ago
PoC-CVE-2025-66224 preview

PoC-CVE-2025-66224

GitHubrichard-natan/poc-cve-2025-66224

Proof-of-concept exploit for CVE-2025-66224 demonstrating remote code execution in OrangeHRM via command injection in the sendmail_path parameter,…

command-and-controldatabase-securityeducation+4
28 months ago
CVE-2021-42667 preview

CVE-2021-42667

GitHub0xdeku/cve-2021-42667

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

database-securityexploitationinformation-gathering+3
24 years ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
27 months ago
CVE-2026-34308 preview

CVE-2026-34308

GitHubjoakimbulow/cve-2026-34308

Proof-of-concept for CVE-2026-34308, a MySQL Server JSON component denial-of-service vulnerability. Demonstrates stack exhaustion via deep $ref…

database-securityexploitationpenetration-testing+1
4 months ago
CVE-2023-31714 preview

CVE-2023-31714

GitHubmsd0pe-1/cve-2023-31714

Proof-of-concept exploit for CVE-2023-31714, a pre-authentication SQL injection in Chitor-CMS < 1.1.2. Automates database enumeration and credential…

database-securityexploitationpenetration-testing+2
14 months ago
cve-2016-6662 preview

cve-2016-6662

GitHubboompig/cve-2016-6662

Exploit code for MySQL remote root code execution and privilege escalation (CVE-2016-6662), including Python and C implementations.

database-securityexploitationpayload-development+3
19 years ago
CVE-2026-10110-SQLi preview

CVE-2026-10110-SQLi

GitHubxmyronn/cve-2026-10110-sqli

Proof-of-concept for unauthenticated SQL injection in Student Details Management System 1.0, demonstrating UNION-based data extraction and credential…

database-securityexploitationpenetration-testing+3
4 months ago
CVE-2025-45809-PoC preview

CVE-2025-45809-PoC

GitHublearner202649/cve-2025-45809-poc

Time-based blind SQL injection proof-of-concept for LiteLLM v1.65.4. Exploits the `/key/block` endpoint to extract database contents and read server…

api-security-testingdatabase-securityeducation+3
3 months ago
CVE-2025-69216 preview

CVE-2025-69216

GitHublukasz-rybak/cve-2025-69216

Proof-of-concept repository for CVE-2025-69216, an authenticated SQL injection in OpenSTAManager's Scadenzario print template, enabling extraction of…

database-securityeducationexploitation+3
4 months ago
Previous1…789…35Next