Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
Geoserver-CVE-2023-25157 preview

Geoserver-CVE-2023-25157

GitHubdr-cable-tv/geoserver-cve-2023-25157

Python-based exploit and detector for GeoServer SQL injection vulnerability CVE-2023-25157, enabling automated target scanning and exploitation.

exploitationpenetration-testingreconnaissance+2
2
2 years ago
SQLRecon preview

SQLRecon

GitHubskahwah/sqlrecon

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

authenticationdatabase-securityexploitation+5
8173 months ago
SQLRecon preview

SQLRecon

GitHubxforcered/sqlrecon

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

database-securityexploitationlateral-movement+6
4001 year ago
CVE-2026-58048-PoC-Exploit preview

CVE-2026-58048-PoC-Exploit

GitHubtc4dy/cve-2026-58048-poc-exploit

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…

database-securityexploitationincident-response+7
51 month ago
CVE-2026-14762-PoC-Exploit preview

CVE-2026-14762-PoC-Exploit

GitHubtc4dy/cve-2026-14762-poc-exploit

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

command-and-controldatabase-securityexploitation+7
22 months ago
phpMyAdmin-CVE-2020-5504-Exploit preview

phpMyAdmin-CVE-2020-5504-Exploit

GitHubcerberusmrxi/phpmyadmin-cve-2020-5504-exploit

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

database-securityexploitationinformation-gathering+5
1 month ago
CVE-2026-9082 preview

CVE-2026-9082

GitHubstrobelpierre/cve-2026-9082

Semi-passive scanner that detects Drupal installations vulnerable to CVE-2026-9082 (PostgreSQL SQL injection) via fingerprinting, version detection,…

database-securityinformation-gatheringreconnaissance+3
4 months ago
PCredz preview

PCredz

GitHublgandx/pcredz

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

forensicsinformation-gatheringnetwork-security+3
2.6k7 months ago
Barcha preview

Barcha

GitHubs1n6h/barcha

Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates: Shodan enumeration of SSL hosts 🕵️‍♂️ Liveness &…

information-gatheringreconnaissancevulnerability-scanners+1
351 year ago
Joomla3.7-SQLi-CVE-2017-8917 preview

Joomla3.7-SQLi-CVE-2017-8917

GitHubbrianwrf/joomla3.7-sqli-cve-2017-8917

Joomla 3.7 SQL injection (CVE-2017-8917)

exploitationinformation-gatheringreconnaissance+2
79 years ago
CVE-2024-3495-Poc preview

CVE-2024-3495-Poc

GitHubtruonghuuphuc/cve-2024-3495-poc

CVE-2024-3495 Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection

exploitationinformation-gatheringpenetration-testing+3
92 years ago
CVE-2023-25157 preview

CVE-2023-25157

GitHub0x2458bughunt/cve-2023-25157

Scans host lists for GeoServer endpoints vulnerable to CVE-2023-25157 SQL injection, verifies exposed paths with keyword checks, and logs confirmed…

exploitationinformation-gatheringreconnaissance+2
103 years ago
CVE-2026-88854 preview

CVE-2026-88854

GitHubmurrez/cve-2026-88854

Python 3 PoC scanner and exploit for CVE-2026-88854, an unauthenticated SQL injection in OrdaSoft Joomla Gallery, with mass check and EXTRACTVALUE…

exploitationpenetration-testingreconnaissance+4
315 days ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
22 days ago
CVE-2026-48842 preview

CVE-2026-48842

GitHubmurrez/cve-2026-48842

Python checker for CVE-2026-48842, a pre-auth SQL injection in Roundcube Webmail's virtuser_query plugin. Detects version, plugin path, and verifies…

exploitationinformation-gatheringpenetration-testing+4
111 days ago
WP2Shell-CVE-2026-63030-POC preview

WP2Shell-CVE-2026-63030-POC

GitHubbhanunamikaze/wp2shell-cve-2026-63030-poc

PoC detector & safe validator for the WP2Shell WordPress vulnerability chain: CVE-2026-63030 (REST batch-route confusion) + CVE-2026-60137…

educationexploitationinformation-gathering+5
2 months ago
abdal-cve-2026-60137 preview

abdal-cve-2026-60137

GitHubebrasha/abdal-cve-2026-60137

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection…

information-gatheringpenetration-testingreconnaissance+2
22 months ago
WP2Shell preview

WP2Shell

GitHubg0d150ne/wp2shell

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

exploitationexploit-frameworkspayload-development+7
11 month ago
Previous1234Next