Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
CVE-2021-21311 preview

CVE-2021-21311

GitHubllhala/cve-2021-21311

Proof-of-concept for CVE-2021-21311, a server-side request forgery in Adminer before 4.7.9, demonstrating SSRF exploitation in PHP database…

exploitationinformation-gatheringpenetration-testing+2
8
4 years ago
CVE-2025-5840 preview

CVE-2025-5840

GitHubhaxerr9/cve-2025-5840

Python-based proof-of-concept exploit for CVE-2025-5840 targeting file upload vulnerabilities in database management systems, enabling remote command…

educationexploitationpayload-generation+3
1 year ago
CVE-2026-56705 preview

CVE-2026-56705

GitHubboreas37/cve-2026-56705

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

educationexploitationlabs-practice+4
21 month ago
CVE-2026-47670 preview

CVE-2026-47670

GitHuberror-inside/cve-2026-47670

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

code-analysiseducationexploitation+4
3 months ago
CVE-2026-7229-SQLI preview

CVE-2026-7229-SQLI

GitHubxmyronn/cve-2026-7229-sqli

Proof of concept for authenticated SQL injection in Coaching Management System, demonstrating database dump via unsanitized complaintreply parameter.

database-securityexploitationpenetration-testing+3
6 months ago
College-Management-System-course_code-SQL-Injection-Authenticated preview

College-Management-System-course_code-SQL-Injection-Authenticated

GitHuberengozaydin/college-management-system-course_code-sql-injection-authenticated

Proof-of-concept demonstrating authenticated SQL injection in College Management System 1.0 via the 'course_code' parameter, with boolean-based blind…

database-securityeducationexploitation+3
4 years ago
CVE-2024-10354 preview

CVE-2024-10354

GitHubk1nakoo/cve-2024-10354

Proof-of-concept exploit for CVE-2024-10354: SQL injection in SourceCodester Petrol Pump Management Software v1.0. Demonstrates unauthenticated…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2026-61511-PoC-Exploit preview

CVE-2026-61511-PoC-Exploit

GitHubtc4dy/cve-2026-61511-poc-exploit

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

database-securityexploitationnetwork-mapping+7
52 months ago
Royal-Event-Management-System-todate-SQL-Injection-Authenticated preview

Royal-Event-Management-System-todate-SQL-Injection-Authenticated

GitHuberengozaydin/royal-event-management-system-todate-sql-injection-authenticated

Authenticated SQL injection exploit for Royal Event Management System 1.0 via the 'todate' parameter, with proof-of-concept payloads and SQLmap…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2024-30998 preview

CVE-2024-30998

GitHubefekaanakkar/cve-2024-30998

Proof-of-concept for CVE-2024-30998: SQL injection vulnerability in PHPGurukul Men Salon Management System 2.0 via the email parameter, enabling…

exploitationpenetration-testingvulnerability-analysis+1
12 years ago
CVE-2025-11077 preview
Archived

CVE-2025-11077

GitHubbytereaper77/cve-2025-11077

Exploit blind SQL Injection in (Online Learning Management System)

exploitationinformation-gatheringpenetration-testing+2
21 year ago
CVE-2024-48427 preview

CVE-2024-48427

GitHubvighneshnair7/cve-2024-48427

Proof-of-concept for CVE-2024-48427: SQL injection in Sourcecodester Packers and Movers Management System v1.0. Exploits the id parameter to execute…

database-securityexploitationinformation-gathering+3
11 year ago
CVE-2025-24799 preview

CVE-2025-24799

GitHubgalisko/cve-2025-24799

Unauthenticated SQL injection exploit for GLPI versions before 10.0.18, enabling database enumeration, credential extraction, and API token…

database-securityexploitationpenetration-testing+3
1 month ago
CVE-2025-59213 preview

CVE-2025-59213

GitHubsynacktiv/cve-2025-59213

Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

database-securityexploitationpenetration-testing+2
34 months ago
CVE-2020-13405 preview

CVE-2020-13405

GitHubmrnazu/cve-2020-13405

MicroWeber Unauthenticated User Database Disclosure - CVE-2020-13405

exploitationinformation-gatheringpenetration-testing+3
12 years ago
CVE-2026-46552 preview

CVE-2026-46552

GitHub0xmrma/cve-2026-46552

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

authentication-authorizationeducationpapers-research+3
3 months ago
CVE-2024-43468 preview

CVE-2024-43468

GitHubsynacktiv/cve-2024-43468

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

database-securityexploitationpenetration-testing+2
966 months ago
CVE-2026-58048-PoC-Exploit preview

CVE-2026-58048-PoC-Exploit

GitHubtc4dy/cve-2026-58048-poc-exploit

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…

database-securityexploitationincident-response+7
52 months ago
Previous123Next