Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
PySQLRecon preview

PySQLRecon

GitHubtw1sm/pysqlrecon

Offensive MSSQL toolkit written in Python, based off SQLRecon

command-and-controldatabase-securityexploitation+3
212
4 months ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
nosqli-flintcms preview

nosqli-flintcms

GitHubnisaruj/nosqli-flintcms

Blind noSQL injection case study lab based on CVE-2018-3783

ctfdatabase-securityeducation+3
43 years ago
Maximo_Sql_Injection-CVE-2019-4650 preview

Maximo_Sql_Injection-CVE-2019-4650

GitHubaneeshanilkumar89/maximo_sql_injection-cve-2019-4650

MAximo SQL Injection Time Based - Oracle DB

database-securityexploitationpenetration-testing+2
1 year ago
nmap preview

nmap

GitHubnmap/nmap

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

bluetooth-securitydatabase-securitydata-exfiltration+18
13.7k13 hours ago
Blisqy preview

Blisqy

GitHubjohntroony/blisqy

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

database-securityexploitationfuzzing+2
4167 years ago
JAW preview

JAW

GitHubsoheilkhodayari/jaw

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

code-analysiscrawlerdatabase-security+5
1197 months ago
Blinder preview

Blinder

GitHubmhaskar/blinder

A python library to automate time-based blind SQL injection

database-securitypenetration-testingvulnerability-analysis+1
507 years ago
CVE-2022-22980 preview

CVE-2022-22980

GitHubtrganda/cve-2022-22980

Proof-of-concept exploit for CVE-2022-22980 targeting Spring Data MongoDB. Demonstrates remote code execution via crafted MongoDB queries. Requires…

database-securityexploitationvulnerability-analysis+1
324 years ago
CVE-2026-2005 preview

CVE-2026-2005

GitHubvar77/cve-2026-2005

PoC for CVE-2026-2005

binary-exploitationdatabase-securityeducation+4
274 months ago
CVE-2022-24706-CouchDB-Exploit preview

CVE-2022-24706-CouchDB-Exploit

GitHubsadshade/cve-2022-24706-couchdb-exploit

Apache CouchDB 3.2.1 - Remote Code Execution (RCE)

database-securityexploitationpenetration-testing+2
294 years ago
CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit preview

CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit

GitHubt0x1cx/cve-2021-36396-moodle-time-based-sqli-exploit

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

database-securityeducationexploitation+3
222 years ago
CVE-2026-78804_Dolibarr_authenticated_SQL_injection preview

CVE-2026-78804_Dolibarr_authenticated_SQL_injection

GitHubrepo4chu/cve-2026-78804_dolibarr_authenticated_sql_injection

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

database-securityexploitationpenetration-testing+4
12 days ago
CVE-2024-51482 preview

CVE-2024-51482

GitHubbridgeralderson/cve-2024-51482

ZenoMinder Blind SQL Injection PoC

database-securityeducationexploitation+4
96 months ago
CVE-2008-5416 preview

CVE-2008-5416

GitHubsecforce/cve-2008-5416

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

database-securityexploitationpenetration-testing+2
39 years ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
21 month ago
CVE-2026-69083_exploit preview

CVE-2026-69083_exploit

GitHub0xdak/cve-2026-69083_exploit

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

database-securitydata-exfiltrationexploitation+2
1 month ago
CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting preview

CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting

GitHubgeorge0papasotiriou/cve-2026-21004-sqlite-fts3-match-infoleak-via-query-crafting

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

database-securitydata-exfiltrationexploitation+1
1 month ago
Previous12Next