Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
11 results
CyberChef preview

CyberChef

GitHubgchq/cyberchef

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

binary-analysiscryptographyctf+9
35.7k
17h 15m ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
1 month ago
nosqli-flintcms preview

nosqli-flintcms

GitHubnisaruj/nosqli-flintcms

Blind noSQL injection case study lab based on CVE-2018-3783

ctfdatabase-securityeducation+3
43 years ago
MongoBleed preview

MongoBleed

GitHubsho-luv/mongobleed

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…

ctfdatabase-securityeducation+6
26 months ago
CVE-2026-2005_lab preview

CVE-2026-2005_lab

GitHubstvm8/cve-2026-2005_lab

Self-contained Docker lab for practicing exploitation of CVE-2026-2005, a heap buffer overflow in PostgreSQL's pgcrypto extension, enabling privilege…

binary-exploitationctfdatabase-security+4
4 months ago
PoC-CVE-2024-44349 preview

PoC-CVE-2024-44349

GitHubandreaf17/poc-cve-2024-44349

Proof-of-concept exploit for CVE-2024-44349, an SQL injection in Anteeo WMS v4.7.x, enabling database dumping and arbitrary SQL query execution.

ctfdatabase-securityeducation+4
19 months ago
CTF_Django_CVE-2022-34265 preview

CTF_Django_CVE-2022-34265

GitHublnwza0x0a/ctf_django_cve-2022-34265

Docker-based CTF challenge demonstrating SQL injection in Django's Trunc() and Extract() database functions (CVE-2022-34265) with UNION-based payload…

ctfdatabase-securityeducation+3
13 years ago
CVE-2012-2122-Home-Lab preview

CVE-2012-2122-Home-Lab

GitHubnetw0rk7/cve-2012-2122-home-lab

CVE-2012-2122 MySQL Authentication Bypass Home Lab

ctfdatabase-securityeducation+3
9 months ago
MongoBleed-exploit preview

MongoBleed-exploit

GitHubeljoamy/mongobleed-exploit

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

ctfdatabase-securityeducation+5
8 months ago
CTF_CVE-2020-7471 preview

CTF_CVE-2020-7471

GitHubtempuss/ctf_cve-2020-7471

CTF challenge exploiting CVE-2020-7471, a Django SQL injection vulnerability in PostgreSQL StringAgg, with Docker setup and exploit scripts.

ctfdatabase-securityeducation+4
5 years ago
CVE-2024-53900 preview

CVE-2024-53900

GitHubgokul-krishnan-v-r/cve-2024-53900

Mongo Vulnub Lab...Try to Hack IT.....!

ctfdatabase-securityeducation+3
1 year ago