Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
sudowp-adminer preview

sudowp-adminer

GitHubsudo-wp/sudowp-adminer

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

authentication-authorizationcloud-securitydatabase-security+3
15 months ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.7k3 days ago
CVE-2024-30896 preview

CVE-2024-30896

GitHubxenom0rph97/cve-2024-30896

Proof-of-concept exploit for CVE-2024-30896, a privilege escalation vulnerability in InfluxDB allowing allAccess token holders to gain operator-level…

authentication-authorizationcloud-securitydatabase-security+3
21 year ago
LDAP-Password-Hunter preview

LDAP-Password-Hunter

GitHuboldboy21/ldap-password-hunter

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

authenticationdatabase-securityinformation-gathering+1
1983 years ago
N1QLMap preview

N1QLMap

GitHubfsecurelabs/n1qlmap

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

database-securitydata-exfiltrationpenetration-testing+1
756 years ago
CVE-2026-39113 preview

CVE-2026-39113

GitHub20000419/cve-2026-39113

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

binary-exploitationcode-analysisdatabase-security+2
16 days ago
CVE-2023-3163-SQL-Injection-Prevention preview

CVE-2023-3163-SQL-Injection-Prevention

GitHubgeorge0papasotiriou/cve-2023-3163-sql-injection-prevention

A simple and quick way to check if your SQL Developer by Oracle is vulnerable to SQL Injection (CVE-2023-3163), most commonly occurs when SQL…

database-securityeducationpenetration-testing+1
43 years ago
Metabase-Setup-Endpoint-SQLi-Fix preview

Metabase-Setup-Endpoint-SQLi-Fix

GitHububitquity/metabase-setup-endpoint-sqli-fix

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

api-securityauthenticationdatabase-security+3
122 days ago
CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting preview

CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting

GitHubgeorge0papasotiriou/cve-2026-21004-sqlite-fts3-match-infoleak-via-query-crafting

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

database-securitydata-exfiltrationexploitation+1
1 month ago
CVE-2024-1346 preview

CVE-2024-1346

GitHubpetergabaldon/cve-2024-1346

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

binary-analysisdatabase-securityexploitation+3
22 years ago
CVE-2024-55963 preview

CVE-2024-55963

GitHubsuperswan/cve-2024-55963

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

database-securityexploitationmisconfiguration+5
21 year ago
bouncer-overflow preview

bouncer-overflow

GitHubnicolasjulian/bouncer-overflow

Working POC of CVE-2026-6664 written by Sonnet 4.6

binary-exploitationdatabase-securityeducation+3
3 months ago
CVE-2024-58290-Xhibiter-SQLi preview

CVE-2024-58290-Xhibiter-SQLi

GitHubsohelyousef/cve-2024-58290-xhibiter-sqli

Proof of Concept (PoC) for SQL Injection in Xhibiter NFT Marketplace 1.10.2 (Collections Endpoint). Discovered by Sohel Yousef.

database-securityexploitationinformation-gathering+3
7 months ago
MongoBleed-DFIR-Triage-Script-CVE-2025-14847 preview

MongoBleed-DFIR-Triage-Script-CVE-2025-14847

GitHubjemhadar/mongobleed-dfir-triage-script-cve-2025-14847

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

container-securitydatabase-securitydigital-forensics+5
8 months ago
moveit-transfer-2023-breach preview

moveit-transfer-2023-breach

GitHubkhengar9274-web/moveit-transfer-2023-breach

Educational case study of the MOVEit Transfer SQL injection breach (CVE-2023-34362) by Cl0p ransomware group, covering attack timeline, exploitation,…

database-securityeducationincident-response+3
7 months ago
CVE-2020-24913-PoC preview

CVE-2020-24913-PoC

GitHubagarma/cve-2020-24913-poc

A Poc for CVE-2020-24913, a SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an…

database-securityexploitationpenetration-testing+2
2 years ago
CVE-2026-78070 preview

CVE-2026-78070

GitHubtoanln-cov/cve-2026-78070

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

database-securityexploitationpenetration-testing+3
3 days ago
Previous1234Next