Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
50 results
Nosql-MongoDB-injection-username-password-enumeration preview

Nosql-MongoDB-injection-username-password-enumeration

GitHuban0nlk/nosql-mongodb-injection-username-password-enumeration

Using this script, you can enumerate Usernames and passwords of Nosql(mongodb) injecion vulnerable web applications.

password-attackspenetration-testingweb-application-exploitation
177
6 years ago
msdat preview

msdat

GitHubquentinhardy/msdat

MSDAT: Microsoft SQL Database Attacking Tool

database-securityexploitationinformation-gathering+3
1.0k3 years ago
SQLRecon preview

SQLRecon

GitHubxforcered/sqlrecon

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

database-securityexploitationlateral-movement+6
4001 year ago
mssqlbof preview

mssqlbof

GitHubmazx0p/mssqlbof

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

authenticationcommand-and-controldatabase-security+8
995 months ago
CVE-2024-51482 preview

CVE-2024-51482

GitHubbridgeralderson/cve-2024-51482

ZenoMinder Blind SQL Injection PoC

database-securityeducationexploitation+4
97 months ago
CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated preview

CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated

GitHubh4md153v63n/cve-2022-40032_simple-task-managing-system-v1.0-sql-injection-vulnerability-unauthenticated

CVE-2022-40032: Simple Task Managing System - 'login' and 'password' SQL Injection (Unauthenticated)

database-securityexploitationpassword-attacks+3
52 years ago
CVE-2026-24418 preview

CVE-2026-24418

GitHubbridgeralderson/cve-2026-24418

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…

database-securityeducationexploitation+5
33 months ago
LabS4U2Self preview

LabS4U2Self

GitHubotterhacker/labs4u2self

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

authentication-authorizationdatabase-securityeducation+5
314 years ago
Athanasius preview

Athanasius

GitHubshyam999/athanasius

Framework for penetration testing. The software can identify everything from cross-site scripting to SQL injection. Developers can also use this…

password-attackspenetration-testingvulnerability-scanners+1
194 years ago
CVE-2019-14314 preview

CVE-2019-14314

GitHubimthoe/cve-2019-14314

Python exploit for CVE-2019-14314: authenticated SQL injection in NextGEN Gallery 3.2.10 WordPress plugin, extracting password hashes from the…

exploitationpassword-attackspenetration-testing+2
86 years ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubfl0ydsec/cve-2026-63030

Python mass exploit and detector for the WordPress Core pre-auth RCE chain CVE-2026-63030 and CVE-2026-60137, chaining SQL injection into remote code…

exploitationpassword-attackspayload-development+7
12 days ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
22 days ago
CVE-2023-0630 preview

CVE-2023-0630

GitHubrandomrobbiebf/cve-2023-0630

CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection

exploitationpassword-attackspenetration-testing+2
23 years ago
CVE-2025-48932-Invision-Community-SQLi-Exploit preview

CVE-2025-48932-Invision-Community-SQLi-Exploit

GitHubcerberusmrxi/cve-2025-48932-invision-community-sqli-exploit

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

data-exfiltrationexploitationinformation-gathering+6
12 months ago
CVE-2022-0439 preview

CVE-2022-0439

GitHubrandomrobbiebf/cve-2022-0439

CVE-2022-0439 - Email Subscribers & Newsletters < 5.3.2 - Subscriber+ Blind SQL injection

exploitationpassword-attackspenetration-testing+2
13 years ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
4 months ago
CVE-2019-9053-Exploit-in-Python-3 preview

CVE-2019-9053-Exploit-in-Python-3

GitHubjason-siu/cve-2019-9053-exploit-in-python-3

Python 3 exploit for CVE-2019-9053 (SQL injection) with hash-cracking, updated from outdated Python 2 code for TryHackMe CTF use.

ctfeducationexploitation+3
2 years ago
CVE-2024-44812-PoC preview

CVE-2024-44812-PoC

GitHubb1u3st0rm/cve-2024-44812-poc

Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0

authentication-authorizationexploitationpassword-attacks+3
2 years ago
Previous123Next