Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
mongoaudit preview

mongoaudit

GitHubstampery/mongoaudit

🔥 A powerful MongoDB auditing and pentesting tool 🔥

authenticationdatabase-securitymisconfiguration+2
1.3k5 years ago
DB_Audit_Research preview

DB_Audit_Research

GitHubmthamil107/db_audit_research

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

adversarial-attackdatabase-securitydefensive-tools+4
1 month ago
pgedge-anonymizer preview

pgedge-anonymizer

GitHubpgedge/pgedge-anonymizer

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

database-securitydata-exfiltrationdevsecops+3
3219 days ago
DBScanner preview

DBScanner

GitHubianxtianxt/dbscanner

未授权访问+弱口令批量检测

database-securityinformation-gatheringmisconfiguration+3
56 years ago
Mongodb-Redis-scan preview

Mongodb-Redis-scan

GitHubianxtianxt/mongodb-redis-scan

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

database-securityinformation-gatheringmisconfiguration+3
46 years ago
CorruptQueryAccessWorkaround preview

CorruptQueryAccessWorkaround

GitHublauxjpn/corruptqueryaccessworkaround

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402

code-analysisdatabase-securitygeneral-purpose-utilities+2
36 years ago
CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable preview

CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable

GitHubgeorge0papasotiriou/cve-2026-11115-database-connection-string-injection-via-env-variable
database-securityeducationexploitation+3
2 months ago
CVE-2024-55963 preview

CVE-2024-55963

GitHubsuperswan/cve-2024-55963

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

database-securityexploitationmisconfiguration+5
21 year ago
cve-2022-22976-bcrypt-skips-salt preview

cve-2022-22976-bcrypt-skips-salt

GitHubspring-io/cve-2022-22976-bcrypt-skips-salt

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

authenticationdatabase-securityencryption-decryption-tools+3
14 years ago
CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 preview

CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026

GitHub14mb1v45h/cyberdudebivash-mongodb-detector-v2026

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

database-securityexploitationinformation-gathering+3
9 months ago
redis-exploitation preview

redis-exploitation

GitHubknqyf263/redis-exploitation

CONFIG SET

database-securityeducationexploitation+3
17 years ago
CVE-2023-49496_PoC preview

CVE-2023-49496_PoC

GitHubhuangyanqwq/cve-2023-49496_poc

Proof-of-concept exploit for CVE-2023-49496, demonstrating SQL injection in UCServer via the /login/wwx_corpInfo/ endpoint to extract sensitive…

database-securityexploitationmisconfiguration+3
1 year ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
8 months ago
CVE-2025-34226 preview

CVE-2025-34226

GitHubeyodav/cve-2025-34226

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.

database-securityexploitationmisconfiguration+3
1 year ago
lblfixer_cve_2022_31181 preview

lblfixer_cve_2022_31181

GitHubdrkbcn/lblfixer_cve_2022_31181

Module for PrestaShop 1.6.1.X/1.7.X to fix CVE-2022-31181 / CVE-2022-36408 vulnerability (Chain SQL Injection)

database-securitymisconfigurationvulnerability-analysis+1
4 years ago
redis-checker preview

redis-checker

GitHubrandomrobbiebf/redis-checker

Checks for exposed Redis servers

database-securityinformation-gatheringmisconfiguration+3
3 years ago
CVE-2021-35576 preview

CVE-2021-35576

GitHubemad-almousa/cve-2021-35576

Proof-of-concept exploit for CVE-2021-35576 demonstrating bypass of Oracle Unified Audit policy via a security vulnerability in database auditing.

database-securityexploitationmisconfiguration+1
4 years ago
CVE-2025-29705 preview

CVE-2025-29705

GitHubyxzrw/cve-2025-29705

CVE-2025-29705

database-securityinformation-gatheringmisconfiguration+2
1 year ago
Previous12Next