Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
100 results
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
3
13 years ago
CVE-2020-11579 preview

CVE-2020-11579

GitHubshieldersec/cve-2020-11579

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

database-securitydata-exfiltrationexploitation+3
252 years ago
CVE-2024-1346 preview

CVE-2024-1346

GitHubpetergabaldon/cve-2024-1346

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

binary-analysisdatabase-securityexploitation+3
22 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHub0xwhoami35/cve-2023-23752

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…

authenticationexploitationinformation-gathering+3
31 year ago
CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE preview

CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50364_csrf_add_category-phpgurukul-cve

Proof-of-concept CSRF exploit targeting CVE-2025-50364 in PHPGurukul Maid Hiring Management System v1.0 that adds arbitrary admin categories via a…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE preview

CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50365_csrf_delete_category-phpgurukul-cve

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

ctfeducationexploitation+3
1 year ago
CVE-2026-40083 preview

CVE-2026-40083

GitHubhakaioffsec/cve-2026-40083

Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…

database-securityeducationexploitation+4
43 months ago
CVE-2022-43117 preview

CVE-2022-43117

GitHubrashidkhanpathan/cve-2022-43117

Proof-of-concept exploit for CVE-2022-43117, a stored XSS vulnerability in Sourcecodester Password Storage Application 1.0, demonstrating JavaScript…

exploitationpenetration-testingvulnerability-analysis+2
13 years ago
WebGoat.NET preview

WebGoat.NET

GitHubowasp/webgoat.net

OWASP WebGoat.NET

code-analysiseducationlabs-practice+3
7313 years ago
D-RAT_VB.NET_MySQL_PHP preview

D-RAT_VB.NET_MySQL_PHP

GitHubmr-wolf-gb/d-rat_vb.net_mysql_php

D-RAT [VB.NET]+[MySQL]+[PHP]

command-and-controlpayload-developmentpenetration-testing+3
146 years ago
cve-2026-5147-exp preview

cve-2026-5147-exp

GitHublan1oc/cve-2026-5147-exp

Exploit script for CVE-2026-5147, performing boolean and time-based blind SQL injection against MySQL interfaces to extract version, database,…

exploitationpenetration-testingvulnerability-analysis+1
6 months ago
warpgate preview

warpgate

GitHubwarp-tech/warpgate

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

authentication-authorizationcloud-infrastructure-securitydatabase-security+4
8.0k6 days ago
CVE-2025-44603-CSRF-Leads_to_Create_FakeUsers preview

CVE-2025-44603-CSRF-Leads_to_Create_FakeUsers

GitHubmoulish2004/cve-2025-44603-csrf-leads_to_create_fakeusers

Proof-of-concept demonstrating a CSRF vulnerability in a PHP-based Client Management System, with HTML exploit code and mitigation strategies for web…

educationexploitationpenetration-testing+3
1 year ago
potential-cassandra preview

potential-cassandra

GitHubcroway/potential-cassandra

CVE discovery

exploitationpayload-generationpenetration-testing+1
12 years ago
metasploitable2 preview

metasploitable2

GitHubunix13/metasploitable2

PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon,…

exploitationmisconfigurationpassword-attacks+3
48 years ago
CVE-2025-21574-Exploit preview

CVE-2025-21574-Exploit

GitHubmdriaz009/cve-2025-21574-exploit

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

database-securityexploitationpassword-attacks+3
1 year ago
dbeaver preview

dbeaver

GitHubdbeaver/dbeaver

Free universal database tool and SQL client

authentication-authorizationcloud-securitydatabase-security+3
52.0k2h 36m ago
Zero-Day-Legacy preview

Zero-Day-Legacy

GitHubayham-megdadi/zero-day-legacy

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

ctfeducationlabs-practice+6
23 months ago
Previous123456Next