Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
CVE-2026-63039 preview

CVE-2026-63039

GitHuboscerd/cve-2026-63039

Proof-of-concept for CVE-2026-63039, demonstrating ORDER BY SQL injection in Apache InLong's AuditAlertRule via orderField/orderType, with a…

educationexploitationpapers-research+2
13h 20m ago
sqlancer preview

sqlancer

GitHubsqlancer/sqlancer

Automated testing to find logic and performance bugs in database systems

database-securityeducationfuzzing+2
1.7k1 day ago
DB_Audit_Research preview

DB_Audit_Research

GitHubmthamil107/db_audit_research

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

adversarial-attackdatabase-securitydefensive-tools+4
5 days ago
bitcoder-v2-research preview

bitcoder-v2-research

GitHubbytepro-ai/bitcoder-v2-research

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

ai-securitycode-analysiseducation+5
113 days ago
CVE-2021-3262 preview

CVE-2021-3262

GitHubl0lsec/cve-2021-3262

Proof-of-concept payloads and annotated HTTP request for blind SQL injection in TripSpark VEO Transportation. Demonstrates out-of-band exploitation…

database-securityeducationexploitation+4
1 month ago
POC-CVE-2026-65971 preview

POC-CVE-2026-65971

GitHubbiitts/poc-cve-2026-65971

Proof-of-concept and technical write-up for CVE-2026-65971 — SQL injection via the sortDirection Livewire property in…

educationexploitationpapers-research+3
1 month ago
CVE-2026-63030-Wp2Shell preview

CVE-2026-63030-Wp2Shell

GitHubghostinexile/cve-2026-63030-wp2shell

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

code-analysiseducationexploitation+3
41 month ago
CVE-2025-14847-mongobleed preview

CVE-2025-14847-mongobleed

GitHubshokribardiya/cve-2025-14847-mongobleed

Python exploit for CVE-2025-14847 targeting uninitialized heap memory disclosure in unauthenticated MongoDB servers via zlib compression.

database-securityeducationexploitation+2
12 months ago
CVE-2025-9776 preview

CVE-2025-9776

GitHubsnailsploit/cve-2025-9776

Proof-of-concept and technical walkthrough for CVE-2025-9776, an authenticated SQL injection in the CatFolders WordPress plugin via CSV import,…

educationexploitationpapers-research+3
3 months ago
CVE-2026-24419 preview

CVE-2026-24419

GitHublukasz-rybak/cve-2026-24419

Documented CVE-2026-24419: SQL injection vulnerability in OpenSTAManager Prima Nota module with PoC, root cause analysis, and recommended fix for…

educationpapers-researchpenetration-testing+2
4 months ago
CVE-2026-33910_SqlInjectionVulnerabilityOpenEMR8.0.0.2 preview

CVE-2026-33910_SqlInjectionVulnerabilityOpenEMR8.0.0.2

GitHubchrissub08/cve-2026-33910_sqlinjectionvulnerabilityopenemr8.0.0.2

Proof-of-concept exploit for CVE-2026-33910, an authenticated SQL injection vulnerability in OpenEMR <8.0.0.3, with detailed analysis, PoC code, and…

educationexploitationpapers-research+3
5 months ago
duckdb preview

duckdb

GitHubjepsen-io/duckdb

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

anomaly-detectiondatabase-securityeducation+2
55 months ago
MOVEit-Transfer-Data-Breach-Analysis. preview

MOVEit-Transfer-Data-Breach-Analysis.

GitHubtubaaiftikhar-ui/moveit-transfer-data-breach-analysis.

Educational analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362), detailing unauthenticated SQL injection exploitation and its global…

database-securityeducationincident-response+3
5 months ago
CVE-2025-67644-LangGraph-3.0.1-SQLite-Checkpoint-SQL-Injection preview

CVE-2025-67644-LangGraph-3.0.1-SQLite-Checkpoint-SQL-Injection

GitHubmbanyamer/cve-2025-67644-langgraph-3.0.1-sqlite-checkpoint-sql-injection

Proof-of-concept exploit for CVE-2025-67644, a SQL injection vulnerability in LangGraph SQLite Checkpoint. Demonstrates arbitrary SQL injection via…

database-securityeducationexploitation+4
16 months ago
CVE-2025-14847-PoC preview

CVE-2025-14847-PoC

GitHubcodeb0ssx/cve-2025-14847-poc

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

database-securityeducationexploitation+3
47 months ago
CVE-2022-33171 preview

CVE-2022-33171

GitHubopen-flaw/cve-2022-33171

Detailed analysis of CVE-2022-33171, a SQL injection vulnerability in TypeORM's findOne() functions, including root cause, impact, and mitigation…

code-analysisdatabase-securityeducation+3
8 months ago
CVE-2025-52399-SQLi-Institute-of-Current-Students preview

CVE-2025-52399-SQLi-Institute-of-Current-Students

GitHubuserr404/cve-2025-52399-sqli-institute-of-current-students

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the loginlinkfaculty endpoint of Institute-of-Current-Students, enabling…

educationexploitationpapers-research+3
11 year ago
CVE-2025-7461 preview

CVE-2025-7461

GitHubbx33661/cve-2025-7461

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

educationpapers-researchvulnerability-analysis+1
41 year ago
Previous12Next