Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
Azure preview

Azure

GitHuboffsecpierogi/azure

Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+8
1
1 month ago
rails-cve-2017-17917 preview

rails-cve-2017-17917

GitHubmatiasarenhard/rails-cve-2017-17917

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

code-analysisdatabase-securityeducation+3
12 years ago
CVE-2020-7471 preview

CVE-2020-7471

GitHubmrlihd/cve-2020-7471

Reproduce CVE-2020-7471

database-securityeducationexploitation+2
5 years ago
CVE-2024-51030 preview

CVE-2024-51030

GitHubvighneshnair7/cve-2024-51030

Proof-of-concept exploit for SQL injection in Sourcecodester Cab Management System 1.0, demonstrating arbitrary SQL execution via the id parameter in…

database-securityexploitationinformation-gathering+3
1 year ago
CVE-2024-10140 preview

CVE-2024-10140

GitHubholypryx/cve-2024-10140

SQL injection exploit script targeting CVE-2024-10140 in the /php/manage_supplier.php endpoint, enabling arbitrary SQL command injection via the id…

database-securityexploitationpenetration-testing+2
21 year ago
CVE-2025-64459-Poc preview

CVE-2025-64459-Poc

GitHub0xcyberstan/cve-2025-64459-poc

Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions:…

database-securityeducationexploitation+3
29 months ago
CVE-2025-69216 preview

CVE-2025-69216

GitHublukasz-rybak/cve-2025-69216

Proof-of-concept repository for CVE-2025-69216, an authenticated SQL injection in OpenSTAManager's Scadenzario print template, enabling extraction of…

database-securityeducationexploitation+3
5 months ago
CVE-2025-69213 preview

CVE-2025-69213

GitHublukasz-rybak/cve-2025-69213

Proof-of-concept repository for CVE-2025-69213, demonstrating a SQL injection vulnerability in OpenSTAManager's ajax_complete.php endpoint with…

database-securityeducationexploitation+3
5 months ago
CVE-2025-69214 preview

CVE-2025-69214

GitHublukasz-rybak/cve-2025-69214

Proof-of-concept for CVE-2025-69214: SQL injection in OpenSTAManager's ajax_select.php componenti endpoint. Includes vulnerable code analysis,…

database-securityeducationexploitation+3
5 months ago
CVE-2026-37149 preview

CVE-2026-37149

GitHubpateldhyeyit/cve-2026-37149

CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in…

database-securityeducationinformation-gathering+3
23 months ago
CVE-2024-48427 preview

CVE-2024-48427

GitHubvighneshnair7/cve-2024-48427

Proof-of-concept for CVE-2024-48427: SQL injection in Sourcecodester Packers and Movers Management System v1.0. Exploits the id parameter to execute…

database-securityexploitationinformation-gathering+3
11 year ago
CVE-2024-50970 preview

CVE-2024-50970

GitHubakhlak2511/cve-2024-50970

Proof-of-concept demonstrating time-based SQL injection in Itsourcecode Online Furniture Shopping Project 1.0 via the id parameter in orderview1.php,…

database-securityeducationexploitation+3
1 year ago
CVE-2025-65950 preview

CVE-2025-65950

GitHublukasz-rybak/cve-2025-65950

Proof-of-concept exploit for a critical time-based blind SQL injection vulnerability in WBCE CMS, enabling low-privileged users to execute arbitrary…

database-securityeducationexploitation+3
5 months ago
CVE-2025-68400 preview

CVE-2025-68400

GitHublukasz-rybak/cve-2025-68400

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

database-securityeducationexploitation+3
5 months ago
CVE-2026-7394-SQLI preview

CVE-2026-7394-SQLI

GitHubxmyronn/cve-2026-7394-sqli

Proof-of-concept exploit for CVE-2026-7394, a SQL injection vulnerability in SourceCodester Pizzafy Ecommerce System 1.0. Demonstrates authenticated…

database-securityexploitationinformation-gathering+3
4 months ago
CVE-2026-24418 preview

CVE-2026-24418

GitHubbridgeralderson/cve-2026-24418

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…

database-securityeducationexploitation+5
22 months ago
pharmacy-sqli-CVE-2026-7392 preview

pharmacy-sqli-CVE-2026-7392

GitHubmicrowaveabi/pharmacy-sqli-cve-2026-7392

SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection

database-securityeducationexploitation+3
3 months ago
SQLRecon preview

SQLRecon

GitHubxforcered/sqlrecon

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

database-securityexploitationlateral-movement+6
3991 year ago
Previous123Next