Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
230 results
php_filter_chains_oracle_exploit_for_CVE-2023-6199 preview

php_filter_chains_oracle_exploit_for_CVE-2023-6199

GitHubabdrrahimdahmani/php_filter_chains_oracle_exploit_for_cve-2023-6199

A CLI to exploit parameters vulnerable to PHP filter chain error based oracle, modified to exploit CVE-2023-6199

exploitationinformation-gatheringpenetration-testing+3
1 year ago
quantumslop preview

quantumslop

GitHubyuvadm/quantumslop

Quantum solver for the Elliptic Curve Discrete Logarithm Problem using Shor's algorithm, implementing multiple oracle strategies to recover ECC…

binary-analysiscryptographyctf+3
266 months ago
CVE-2026-21962-o preview

CVE-2026-21962-o

GitHubgregk4sec/cve-2026-21962-o

Proof-of-concept for CVE-2026-21962, a critical unauthenticated remote vulnerability in Oracle HTTP Server and WebLogic Proxy Plug-in, demonstrating…

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
CVE-2021-35576 preview

CVE-2021-35576

GitHubemad-almousa/cve-2021-35576

Proof-of-concept exploit for CVE-2021-35576 demonstrating bypass of Oracle Unified Audit policy via a security vulnerability in database auditing.

database-securityexploitationmisconfiguration+1
4 years ago
CVE-2023-22047 preview

CVE-2023-22047

GitHubtuo4n8/cve-2023-22047

Leveraging arbitrary file read to RCE on Oracle PeopleSoft

exploitationinformation-gatheringpenetration-testing+3
121 year ago
CVE-2024-20931_weblogic preview

CVE-2024-20931_weblogic

GitHubatonysan/cve-2024-20931_weblogic

Standalone proof-of-concept for CVE-2024-20931 targeting Oracle WebLogic Server to trigger remote code execution in unpatched deployments.

exploitationpenetration-testingvulnerability-analysis+1
12 years ago
CVE-2023-3163-SQL-Injection-Prevention preview

CVE-2023-3163-SQL-Injection-Prevention

GitHubgeorge0papasotiriou/cve-2023-3163-sql-injection-prevention

A simple and quick way to check if your SQL Developer by Oracle is vulnerable to SQL Injection (CVE-2023-3163), most commonly occurs when SQL…

database-securityeducationpenetration-testing+1
43 years ago
php_filter_chains_oracle_exploit preview

php_filter_chains_oracle_exploit

GitHubsynacktiv/php_filter_chains_oracle_exploit

A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.

exploitationinformation-gatheringpenetration-testing+2
3352 years ago
CVE-2024-21111 preview

CVE-2024-21111

GitHubmansk1es/cve-2024-21111

Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability

binary-exploitationexploitationpenetration-testing+3
2162 years ago
CVE-2020-2950 preview

CVE-2020-2950

GitHubtuo4n8/cve-2020-2950

Proof-of-concept exploit for CVE-2020-2950, demonstrating AMF deserialization to Java deserialization in Oracle Business Intelligence, with debug…

binary-analysisexploitationpenetration-testing+2
5 years ago
the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss preview

the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

GitHubhunt-benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

android-securitydynamic-analysis-sandboxingexploitation+6
29 days ago
ONe-TIME-ecb-oracle-attack-AES preview

ONe-TIME-ecb-oracle-attack-AES

GitHubspiralbl0ck/one-time-ecb-oracle-attack-aes

Implementation of the byte-at-a-time ECB oracle attack against AES-ECB encryption. Decrypts ciphertexts by feeding chosen plaintexts to a block…

cryptographyeducationexploitation+1
15 years ago
weblogic_honeypot preview

weblogic_honeypot

GitHubcymmetria/weblogic_honeypot

WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is…

defensive-toolsexploitationvulnerability-scanners+1
336 years ago
micros_honeypot preview

micros_honeypot

GitHubcymmetria/micros_honeypot

MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications…

defensive-toolsincident-responsevulnerability-scanners+1
188 years ago
CVE-2019-2890 preview

CVE-2019-2890

GitHubianxtianxt/cve-2019-2890

PoC exploit for CVE-2019-2890 targeting Oracle WebLogic, using JRMP deserialization to achieve remote command execution via ysoserial payloads.

command-and-controlexploitationpayload-generation+3
46 years ago
o5logon-fetch preview

o5logon-fetch

GitHubhantwister/o5logon-fetch

Attempts to exploit CVE-2012-3137 on vulnerable Oracle servers

database-securityexploitationpassword-cracking+2
312 years ago
CVE-2010-3600-PythonHackOracle11gR2 preview

CVE-2010-3600-PythonHackOracle11gR2

GitHublaitrungminhduc/cve-2010-3600-pythonhackoracle11gr2

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

database-securityexploitationpenetration-testing+1
28 years ago
CVE-2024-21111 preview

CVE-2024-21111

GitHubx0rsys/cve-2024-21111

Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16

binary-exploitationexploitationpenetration-testing+2
22 years ago
Previous1234…13Next