Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Payload Generation

Tools for creating and customizing malicious code or instructions to execute after exploitation.

NewestRelevanceMost popularRecently updated
3373 results
cve-2026-69243-poc-aiohttp-smuggling preview

cve-2026-69243-poc-aiohttp-smuggling

GitHubjvbotelho/cve-2026-69243-poc-aiohttp-smuggling
payload-generationvulnerability-analysisexploitation+3
1
16 days ago
Zhilly preview

Zhilly

GitLabsacriphanius/zhilly

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF…

embedded-systems-securityreconnaissanceiot-security+6
116 days ago
Fritter preview

Fritter

GitHub0xrootpls/fritter

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

payload-generationexploitationshellcode+5
24816 days ago
CVE-2026-17566 preview

CVE-2026-17566

GitHubhackspeak/cve-2026-17566

pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch

payload-generationvulnerability-analysisexploitation+3
116 days ago
CVE-2026-52680_exploit preview

CVE-2026-52680_exploit

GitHub0xdak/cve-2026-52680_exploit
payload-generationpersistence-mechanismsexploitation+3
17 days ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

phishing-toolspayload-generationinformation-gathering+5
95117 days ago
CVE-2026-63223 preview

CVE-2026-63223

GitHubshinthink/cve-2026-63223

CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434…

web-vulnerability-scannerspayload-generationvulnerability-analysis+3
117 days ago
CVE-2026-21013-PDF-JavaScript-Injection-via-Embedded-Script preview

CVE-2026-21013-PDF-JavaScript-Injection-via-Embedded-Script

GitHubgeorge0papasotiriou/cve-2026-21013-pdf-javascript-injection-via-embedded-script
payload-generationvulnerability-analysisexploitation+1
17 days ago
CVE-2026-11112-XXE-via-SVG-Image-Upload preview

CVE-2026-11112-XXE-via-SVG-Image-Upload

GitHubgeorge0papasotiriou/cve-2026-11112-xxe-via-svg-image-upload
payload-generationvulnerability-analysisexploitation+3
17 days ago
MemShellParty preview

MemShellParty

GitHubreajason/memshellparty

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

exploit-frameworkspayload-generationweb-application-exploitation+3
1.6k17 days ago
CVE-2026-63223-POC preview

CVE-2026-63223-POC

GitHubimbas007/cve-2026-63223-poc

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

payload-generationvulnerability-analysisexploitation+5
118 days ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubgbuyssens/cve-2026-39987

Marimo exploit prior to 0.23.0. Pre-Auth RCE vulnerability via websocket endpoint : /terminal/ws.

payload-generationexploitationweb-application-exploitation+3
18 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubjenderal92/cve-2026-49049

Mass scanner for Joomla Helix3 CVE-2026-49049 that uploads PHP test payloads via com_ajax and detects executed (RCE) or raw PHP responses.

vulnerability-scannersweb-vulnerability-scannerspayload-generation+4
19 days ago
Empire preview

Empire

GitHubbc-security/empire

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

penetration-testing-frameworkspayload-generationids-ips-evasion+5
5.2k19 days ago
CVE-2022-24355 preview

CVE-2022-24355

GitHubilizavr/cve-2022-24355

Tplink wr841 v10 rce exploit without authorisation

payload-generationvulnerability-analysisexploitation+3
20 days ago
CVE-2020-16898 preview
Archived

CVE-2020-16898

GitHubzephrfish/cve-2020-16898

HoneyPoC 2.0: Proof-of-Concept (PoC) script to exploit IPv6 (CVE-2020-16898).

payload-generationvulnerability-analysisexploitation+3
2221 days ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubheltonpojo/cve-2025-32432

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

authentication-authorizationpayload-generationexploitation+3
21 days ago
CVE-2026-65883 preview

CVE-2026-65883

GitHubshinthink/cve-2026-65883

Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 |…

payload-generationvulnerability-analysisexploitation+4
21 days ago
Previous1…456…188Next