Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
CVE-2026-23921 preview

CVE-2026-23921

GitHubqucklecrabik/cve-2026-23921

Proof-of-concept exploit for CVE-2026-23921, a time-based blind SQL injection in Zabbix API via the sortfield parameter, enabling data extraction…

database-securityexploitationpenetration-testing+3
3 days ago
CVE-2026-78804_Dolibarr_authenticated_SQL_injection preview

CVE-2026-78804_Dolibarr_authenticated_SQL_injection

GitHubrepo4chu/cve-2026-78804_dolibarr_authenticated_sql_injection

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

database-securityexploitationpenetration-testing+4
15 days ago
CVE-2023-6567-poc preview

CVE-2023-6567-poc

GitHubmimiloveexe/cve-2023-6567-poc

Proof-of-concept exploit for a time-based blind SQL injection in the LearnPress WordPress plugin, allowing unauthenticated attackers to extract…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
SQLi_Sleeps preview

SQLi_Sleeps

GitHubhernanrodriguez1/sqli_sleeps

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

penetration-testingweb-application-exploitationweb-security+1
1261 year ago
requests-racer preview

requests-racer

GitHubnccgroup/requests-racer

Small Python library that makes it easy to exploit race conditions in web apps with Requests.

penetration-testingvulnerability-analysisweb-application-exploitation+1
1613 years ago
CVE-2026-49048-JoomCCK-SQLi preview

CVE-2026-49048-JoomCCK-SQLi

GitHubkara-git/cve-2026-49048-joomcck-sqli

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

database-securityexploitationpenetration-testing+3
12 months ago
CVE-2025-22964 preview

CVE-2025-22964

GitHubpadayali-jd/cve-2025-22964

Proof-of-concept exploit for CVE-2025-22964, a time-based blind SQL injection vulnerability in DDSN Interactive cm3 Acora CMS 10.1.1, enabling…

database-securitypenetration-testingvulnerability-analysis+2
11 year ago
CVE-2024-8856 preview

CVE-2024-8856

GitHububaydev/cve-2024-8856

WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability

exploitationpayload-developmentpenetration-testing+3
21 year ago
CVE-2017-6913 preview

CVE-2017-6913

GitHubgquere/cve-2017-6913

Stored XSS proof-of-concept exploit for open-xchange OX App Suite webmail, demonstrating unescaped HTML time tag event attributes leading to…

exploitationpenetration-testingvulnerability-analysis+2
28 years ago
CVE-2025-14124 preview

CVE-2025-14124

GitHubhyunchiya/cve-2025-14124

Unauthenticated SQL Injection (Time-Based Blind)

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
194 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHub0xrar/cve-2021-41773

Exploit for Apache 2.4.49

exploitationpenetration-testingvulnerability-analysis+2
74 years ago
CVE-2025-55575 preview

CVE-2025-55575

GitHubaether-0/cve-2025-55575

Time-based SQL injection detection template for SMM Panel targeting the service_detail parameter via crafted POST requests to /ajax_data, using…

exploitationpenetration-testingvulnerability-analysis+3
3281 year ago
reflector preview

reflector

GitHubelkokc/reflector

Burp plugin able to find reflected XSS on page in real-time while browsing on site

penetration-testingvulnerability-scannersweb-application-exploitation+1
1.2k5 years ago
ScanQLi preview

ScanQLi

GitHubbambish/scanqli

SQLi scanner to detect SQL vulns

penetration-testingvulnerability-scannersweb-security
2057 years ago
Blinder preview

Blinder

GitHubmhaskar/blinder

A python library to automate time-based blind SQL injection

database-securitypenetration-testingvulnerability-analysis+1
507 years ago
xssmap preview

xssmap

GitHubjewel591/xssmap

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…

penetration-testingvulnerability-analysisweb-security+1
2716 years ago
Previous12Next