Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
CVE-2026-23921 preview

CVE-2026-23921

GitHubqucklecrabik/cve-2026-23921

Proof-of-concept exploit for CVE-2026-23921, a time-based blind SQL injection in Zabbix API via the sortfield parameter, enabling data extraction…

database-securityexploitationpenetration-testing+3
4 days ago
CVE-2026-78804_Dolibarr_authenticated_SQL_injection preview

CVE-2026-78804_Dolibarr_authenticated_SQL_injection

GitHubrepo4chu/cve-2026-78804_dolibarr_authenticated_sql_injection

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

database-securityexploitationpenetration-testing+4
16 days ago
CVE-2024-36058 preview

CVE-2024-36058

GitHubhacklantic/cve-2024-36058

Proof-of-concept exploit and advisory for CVE-2024-36058, a time-based blind SQL injection in Koha Library Software's opac-sendbasket.pl, enabling…

exploitationpenetration-testingvulnerability-analysis+1
22 days ago
microsoft-cve-2021-1675 preview
Archived

microsoft-cve-2021-1675

GitHubthalpius/microsoft-cve-2021-1675

Proof-of-concept C# exploit for CVE-2021-1675 (Windows Print Spooler elevation of privilege), accepting custom driver and DLL paths for targeted…

exploitationpenetration-testingprivilege-escalation
1 month ago
CVE-2026-49048-JoomCCK-SQLi preview

CVE-2026-49048-JoomCCK-SQLi

GitHubkara-git/cve-2026-49048-joomcck-sqli

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

database-securityexploitationpenetration-testing+3
12 months ago
wp2shell preview

wp2shell

GitHublutfifakee-project/wp2shell

wp2shell - WordPress CVE-2026-63030 Exploit & Scanner

exploitationpenetration-testingremote-access-tool+2
62 months ago
pywhisker preview

pywhisker

GitHubshutdownrepo/pywhisker

Python version of the C# tool for "Shadow Credentials" attacks

authenticationexploitationpenetration-testing+1
9393 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubmidox008/cve-2026-24061

GNU Inetutils telnetd Remote Authentication Bypass

exploitationpenetration-testingremote-access-tool+2
5 months ago
CVE-2024-51482-ZoneMinder-CCTV-HTB-Reliable-EXP preview

CVE-2024-51482-ZoneMinder-CCTV-HTB-Reliable-EXP

GitHuberhui-li/cve-2024-51482-zoneminder-cctv-htb-reliable-exp

Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and…

ctfexploitationpenetration-testing+2
6 months ago
CTT-Sovereign-Vortex preview

CTT-Sovereign-Vortex

GitHubsimoesctt/ctt-sovereign-vortex

Exploit for CVE-2026-2406 targeting Terrminus Authentication Gateways, using temporal dispersion to bypass fingerprinting and behavioral AI,…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2025-14124 preview

CVE-2025-14124

GitHubhyunchiya/cve-2025-14124

Unauthenticated SQL Injection (Time-Based Blind)

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
React2Shell preview

React2Shell

GitLabletchupkt/react2shell

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

command-and-controlexploitationpenetration-testing+3
19 months ago
CVE-2025-63585 preview

CVE-2025-63585

GitHubkgan0509/cve-2025-63585

Proof-of-concept for a blind time-based SQL injection vulnerability in OSSN's /action/rtcomments/status endpoint, demonstrating arbitrary SQL…

database-securityexploitationpenetration-testing+2
10 months ago
CVE-2025-55575 preview

CVE-2025-55575

GitHubaether-0/cve-2025-55575

Time-based SQL injection detection template for SMM Panel targeting the service_detail parameter via crafted POST requests to /ajax_data, using…

exploitationpenetration-testingvulnerability-analysis+3
3281 year ago
TimeInjector preview

TimeInjector

GitHubbreadsquad/timeinjector

Time injector is a CVE-2018-14714 exploitation script

command-and-controlexploitationpenetration-testing+2
1 year ago
CVE-2025-5287 preview

CVE-2025-5287

GitHubwiseep/cve-2025-5287

Wordpress likes and dislikes add-on - SQL Injection

exploitationpenetration-testingvulnerability-analysis+1
101 year ago
CVE-2025-28346 preview

CVE-2025-28346

GitHubshubham03007/cve-2025-28346

Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter

database-securityexploitationpenetration-testing+2
11 year ago
CVE-2024-6387_PoC preview

CVE-2024-6387_PoC

GitHubyassdev221608/cve-2024-6387_poc

Scans and exploits CVE-2024-6387 (regreSSHion) in OpenSSH servers. Features multi-threaded scanning, banner retrieval, grace time detection, and…

exploitationnetwork-securitypenetration-testing+2
161 year ago
Previous123Next