Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
LDAP-Password-Hunter preview

LDAP-Password-Hunter

GitHuboldboy21/ldap-password-hunter

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

authenticationdatabase-securityinformation-gathering+1
198
3 years ago
CVE-2024-58290-Xhibiter-SQLi preview

CVE-2024-58290-Xhibiter-SQLi

GitHubsohelyousef/cve-2024-58290-xhibiter-sqli

Proof of Concept (PoC) for SQL Injection in Xhibiter NFT Marketplace 1.10.2 (Collections Endpoint). Discovered by Sohel Yousef.

database-securityexploitationinformation-gathering+3
8 months ago
LeakLooker preview
Archived

LeakLooker

GitHubwoj-ciech/leaklooker

Find open databases - Powered by Binaryedge.io

cloud-securitydatabase-securityinformation-gathering+5
1.5k6 years ago
Nosql-Exploitation-Framework preview

Nosql-Exploitation-Framework

GitHubtorque59/nosql-exploitation-framework

A Python Framework For NoSQL Scanning and Exploitation

database-securityexploitationinformation-gathering+3
6048 years ago
CVE-2025-50565 preview

CVE-2025-50565

GitHubm0b1u3/cve-2025-50565

Proof-of-concept exploit for an SQL injection vulnerability in Doubo ERP 1.0, enabling remote attackers to extract sensitive database information.

database-securityinformation-gatheringpenetration-testing+2
1 year ago
CVE-2025-29529 preview

CVE-2025-29529

GitHubyoshik0xf6/cve-2025-29529

SQLi ITC Multiplan v3.7.4.1002 (CVE-2025-29529)

database-securityexploitationinformation-gathering+3
1 year ago
N1QLMap preview

N1QLMap

GitHubfsecurelabs/n1qlmap

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

database-securitydata-exfiltrationpenetration-testing+1
766 years ago
CVE-2023-3163-SQL-Injection-Prevention preview

CVE-2023-3163-SQL-Injection-Prevention

GitHubgeorge0papasotiriou/cve-2023-3163-sql-injection-prevention

A simple and quick way to check if your SQL Developer by Oracle is vulnerable to SQL Injection (CVE-2023-3163), most commonly occurs when SQL…

database-securityeducationpenetration-testing+1
43 years ago
CVE-2026-78070 preview

CVE-2026-78070

GitHubtoanln-cov/cve-2026-78070

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

database-securityexploitationpenetration-testing+3
1 month ago
CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting preview

CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting

GitHubgeorge0papasotiriou/cve-2026-21004-sqlite-fts3-match-infoleak-via-query-crafting

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

database-securitydata-exfiltrationexploitation+1
2 months ago
CVE-2026-39113 preview

CVE-2026-39113

GitHub20000419/cve-2026-39113

Advisory and AddressSanitizer reproducer for a SQLite SQLAR heap-buffer-overflow triggered by a crafted SZ value causing truncated allocation and…

binary-exploitationcode-analysisdatabase-security+2
1 month ago
Metabase-Setup-Endpoint-SQLi-Fix preview

Metabase-Setup-Endpoint-SQLi-Fix

GitHububitquity/metabase-setup-endpoint-sqli-fix

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

api-securityauthenticationdatabase-security+3
11 month ago
CVE-2024-1346 preview

CVE-2024-1346

GitHubpetergabaldon/cve-2024-1346

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

binary-analysisdatabase-securityexploitation+3
22 years ago
CVE-2024-55963 preview

CVE-2024-55963

GitHubsuperswan/cve-2024-55963

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

database-securityexploitationmisconfiguration+5
21 year ago
bouncer-overflow preview

bouncer-overflow

GitHubnicolasjulian/bouncer-overflow

Working POC of CVE-2026-6664 written by Sonnet 4.6

binary-exploitationdatabase-securityeducation+3
5 months ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
sudowp-adminer preview

sudowp-adminer

GitHubsudo-wp/sudowp-adminer

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

authentication-authorizationcloud-securitydatabase-security+3
16 months ago
MongoBleed-DFIR-Triage-Script-CVE-2025-14847 preview

MongoBleed-DFIR-Triage-Script-CVE-2025-14847

GitHubjemhadar/mongobleed-dfir-triage-script-cve-2025-14847

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

container-securitydatabase-securitydigital-forensics+5
9 months ago
Previous1234Next