Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
293 results
CVE-2024-34693 preview

CVE-2024-34693

GitHubmr-r00t11/cve-2024-34693

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

database-securitydata-exfiltrationexploitation+3
2 years ago
cve-2026-9082-drupal-postgresql-rce preview

cve-2026-9082-drupal-postgresql-rce

GitHubambionics/cve-2026-9082-drupal-postgresql-rce

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

binary-exploitationdatabase-securityeducation+7
113 months ago
mongobleed preview

mongobleed

GitHubadolfbharath/mongobleed

CVE-2025-14847 explaination and lab

cryptographydatabase-securityeducation+3
17 months ago
CVE-2025-64513 preview

CVE-2025-64513

GitHubshinyseam/cve-2025-64513

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

authenticationdatabase-securityexploitation+3
19 months ago
CVE-2018-1058 preview

CVE-2018-1058

GitHubccchme/cve-2018-1058

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

database-securityeducationexploitation+3
3 months ago
NetExec preview

NetExec

GitHubpennyw0rth/netexec

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

command-and-controldatabase-securityexploitation+14
5.8k1 day ago
CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit preview

CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit

GitHubt0x1cx/cve-2021-36396-moodle-time-based-sqli-exploit

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

database-securityeducationexploitation+3
222 years ago
CVE-2025-32429 preview

CVE-2025-32429

GitHubamir-othman/cve-2025-32429

Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only

database-securityeducationexploitation+3
1 year ago
CVE-2025-14847---MongoBleed preview

CVE-2025-14847---MongoBleed

GitHubsaereya/cve-2025-14847---mongobleed

Go proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a MongoDB memory disclosure vulnerability. Crafts malformed BSON documents to leak…

database-securityeducationexploitation+3
8 months ago
CVE-2022-21661-Demo preview

CVE-2022-21661-Demo

GitHubdaniel616/cve-2022-21661-demo

Demonstration of the SQL injection vulnerability in wordpress 5.8.2

database-securityeducationlabs-practice+3
23 years ago
CVE-2025-14847-MongoDB preview

CVE-2025-14847-MongoDB

GitHubinfosecantara/cve-2025-14847-mongodb

Educational research tool demonstrating CVE-2025-14847 memory disclosure in MongoDB's BSON decompression. Simulates bounds-checking failures and…

database-securityeducationexploitation+3
16 months ago
CVE_2022_3141 preview

CVE_2022_3141

GitHubtomoe-12/cve_2022_3141

Detailed security analysis and proof-of-concept for CVE-2022-3141, an unauthenticated SQL injection in ACS EDU 3rd Gen, including reproduction steps…

database-securityeducationexploitation+3
111 months ago
CVE-2025-69216 preview

CVE-2025-69216

GitHublukasz-rybak/cve-2025-69216

Proof-of-concept repository for CVE-2025-69216, an authenticated SQL injection in OpenSTAManager's Scadenzario print template, enabling extraction of…

database-securityeducationexploitation+3
4 months ago
CVE-2026-65761 preview

CVE-2026-65761

GitHubywh-jfellus/cve-2026-65761

Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`

database-securityeducationlabs-practice+2
29 days ago
CVE-2025-11391 preview

CVE-2025-11391

GitHubmoritakaaz/cve-2025-11391

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

database-securityeducationexploitation+4
10 months ago
CVE-2025-69213 preview

CVE-2025-69213

GitHublukasz-rybak/cve-2025-69213

Proof-of-concept repository for CVE-2025-69213, demonstrating a SQL injection vulnerability in OpenSTAManager's ajax_complete.php endpoint with…

database-securityeducationexploitation+3
4 months ago
CVE-2025-14847-PoC preview

CVE-2025-14847-PoC

GitHubcodeb0ssx/cve-2025-14847-poc

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

database-securityeducationexploitation+3
48 months ago
bouncer-overflow preview

bouncer-overflow

GitHubnicolasjulian/bouncer-overflow

Working POC of CVE-2026-6664 written by Sonnet 4.6

binary-exploitationdatabase-securityeducation+3
3 months ago
Previous12…17Next