#1Tools for creating and customizing malicious code or instructions to execute after exploitation.
Kitploit recommended

Some tools to help mitigating Apache Log4j 2 CVE-2021-44228
High CVE-2024-4761 Exploit

CVE-2022-24990 exploit tool with POC detection and EXP WebShell upload for TerraMaster NAS devices. Supports URL-based targeting and dual-mode…

Graphical detection tool for CVE-2022-22965 (Spring4Shell) with one-click reverse shell generation, command execution, and multi-server shell path…

Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV

SonLogger Vulns (CVE-2021-27963, CVE-2021-27964)


CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod…

Python proof-of-concept exploit for CVE-2026-33017, an unauthenticated remote code execution vulnerability in Langflow. Delivers a reverse shell via…

Pre-auth RCE scanner for Langflow < 1.8.0 — Route Injection + Vertex Injection → Code Execution (CVSS 9.8)

Authenticated path traversal and arbitrary file write PoC exploit for Casdoor <3.54.1, enabling RCE via SSH key injection, web shell upload, or…

Proof-of-concept exploit for CVE-2026-9277, a command injection vulnerability in shell-quote library. Performs recursive JSON traversal with…

Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter

CVE-2019-0232 - Apache Tomcat CGIServlet enableCmdLineArguments RCE - PoC Exploit

ZIP Bomb Creator is a tool used to create a ZIP file that is small in size but drastically expands when extracted.

Python exploit for CVE-2020-14008 in ManageEngine Applications Manager delivering a SYSTEM-level reverse shell via authenticated remote code…

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.