Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
mariadb-13-rce-lab preview

mariadb-13-rce-lab

GitHubdinosn/mariadb-13-rce-lab

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

binary-exploitationdatabase-securityexploitation+5
67
2 months ago
redis-post-exploitation preview

redis-post-exploitation

GitHubknqyf263/redis-post-exploitation

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

database-securityeducationexploitation+3
35 years ago
melee preview

melee

GitHubadityaks/melee

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

database-securityincident-responsemalware-analysis+2
233 years ago
CVE-2022-24706-CouchDB-Exploit preview

CVE-2022-24706-CouchDB-Exploit

GitHubsadshade/cve-2022-24706-couchdb-exploit

Apache CouchDB 3.2.1 - Remote Code Execution (RCE)

database-securityexploitationpenetration-testing+2
294 years ago
Reproduce-CVE-2024-21513 preview

Reproduce-CVE-2024-21513

GitHubsavagesanta11/reproduce-cve-2024-21513

Demonstrates CVE-2024-21513 in langchain-experimental, showing arbitrary code execution via VectorSQLDatabaseChain's eval() on retrieved values.…

code-analysisdatabase-securityeducation+3
1 year ago
CVE-2025-1094-PoC-Postgre-SQLi preview

CVE-2025-1094-PoC-Postgre-SQLi

GitHubishwardeepp/cve-2025-1094-poc-postgre-sqli

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

code-analysisdatabase-securityeducation+5
61 year ago
JAW preview

JAW

GitHubsoheilkhodayari/jaw

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

code-analysiscrawlerdatabase-security+5
1187 months ago
CVE-2024-55963 preview

CVE-2024-55963

GitHubsuperswan/cve-2024-55963

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

database-securityexploitationmisconfiguration+5
21 year ago
CVE-2019-9193-Postgresql-RCE preview

CVE-2019-9193-Postgresql-RCE

GitHubcybersrmutl/cve-2019-9193-postgresql-rce

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

command-and-controldatabase-securityexploitation+2
8 months ago
CVE-2024-56429 preview

CVE-2024-56429

GitHublisa-2905/cve-2024-56429

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

database-securityexploitationpassword-attacks+2
1 year ago
CVE-2023-39593 preview

CVE-2023-39593

GitHubant1sec-ops/cve-2023-39593

Database authenticated code execution

command-and-controldatabase-securityeducation+6
21 year ago
Mysql_CVE-2024-27766 preview

Mysql_CVE-2024-27766

GitHubhissec/mysql_cve-2024-27766

Database authenticated code execution

database-securityeducationexploitation+3
2 years ago
CVE-2024-53900 preview

CVE-2024-53900

GitHubgokul-krishnan-v-r/cve-2024-53900

Mongo Vulnub Lab...Try to Hack IT.....!

ctfdatabase-securityeducation+3
1 year ago
prowler preview

prowler

GitHubprowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+10
14.9k3 days ago
EDRaser preview

EDRaser

GitHubsafebreach-labs/edraser

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

database-securitypost-exploitation
3722 years ago
mysqld_safe-CVE-2016-6662-patch preview

mysqld_safe-CVE-2016-6662-patch

GitHubkonstantin-kelemen/mysqld_safe-cve-2016-6662-patch

Ansible playbook that applies the Percona patch for CVE-2016-6662 to the mysqld_safe file on CentOS and FreeBSD systems.

configuration-auditingdatabase-securitydevsecops+1
10 years ago
ecapture preview

ecapture

GitHubgojue/ecapture

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

android-securitydatabase-securitydynamic-analysis-sandboxing+3
15.5k7h 41m ago
CVE-2025-46817 preview

CVE-2025-46817

GitHubdwisiswant0/cve-2025-46817

Proof-of-concept for Redis Lua unpack integer overflow (CVE-2025-46817) demonstrating stack blow-up and potential RCE on Redis 8.2.1.

binary-exploitationdatabase-securityexploitation+2
30 years ago
Previous1234Next