Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
142 results
CVE-2024-22274-RCE preview

CVE-2024-22274-RCE

GitHubl0n3m4n/cve-2024-22274-rce

PoC - Authenticated Remote Code Execution in VMware vCenter Server (Exploit)

command-and-controlexploitationpenetration-testing+3
472 years ago
CVE-2026-34156-NocoBase-Sandbox-Escape-via-Workflow-Execution-Vulnerability- preview

CVE-2026-34156-NocoBase-Sandbox-Escape-via-Workflow-Execution-Vulnerability-

GitHubdhananjayasj/cve-2026-34156-nocobase-sandbox-escape-via-workflow-execution-vulnerability-

Authenticated RCE exploit for NocoBase workflow engine sandbox escape (CVE-2026-34156). Executes arbitrary system commands via crafted workflow…

command-and-controlexploitationpenetration-testing+3
2 months ago
exploit-CVE-2022-36779 preview

exploit-CVE-2022-36779

GitHubrootdr-backup/exploit-cve-2022-36779

Authenticated command injection exploit for CVE-2022-36779, enabling remote code execution on vulnerable web applications.

command-and-controlexploitationpenetration-testing+2
1 year ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubk3ystr0k3r/cve-2026-24061

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

authenticationauthentication-authorizationcommand-and-control+8
32 months ago
CVE-2024-41570 preview

CVE-2024-41570

GitHubdiemoeve/cve-2024-41570

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

command-and-controlexploitationpayload-generation+5
121 year ago
CVE-2020-14750 preview

CVE-2020-14750

GitHubpprietosanchez/cve-2020-14750

PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882

command-and-controlexploitationpenetration-testing+2
485 years ago
CVE-2025-26055 preview

CVE-2025-26055

GitHubrohan-pt/cve-2025-26055

CVE Description

command-and-controlexploitationpenetration-testing+2
1 year ago
LOG4J-CVE-2021-44228 preview
Archived

LOG4J-CVE-2021-44228

GitHubsumitpathania03/log4j-cve-2021-44228

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including vulnerable server setup, exploit…

command-and-controlexploitationpacket-sniffing-analysis+3
3 years ago
cve-2017-5123 preview

cve-2017-5123

GitHubnabilboudra/cve-2017-5123

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

binary-exploitationcommand-and-controleducation+5
8 months ago
DblTekGoIPPwn preview

DblTekGoIPPwn

GitHubjacobmisirian/dbltekgoippwn

Tool to check if an IP of a DblTek GoIP is vulnerable to a challenge-response login system, send SMS messages from the system, execute remote…

command-and-controlexploitationpenetration-testing+2
636 years ago
poc-proxycommand-vulnerable preview

poc-proxycommand-vulnerable

GitHubvin01/poc-proxycommand-vulnerable

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

command-and-controlexploitationlateral-movement+3
502 years ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
fortios-auth-bypass-exploit-CVE-2024-55591 preview

fortios-auth-bypass-exploit-CVE-2024-55591

GitHubsysirq/fortios-auth-bypass-exploit-cve-2024-55591

Python exploit for CVE-2024-55591, bypassing FortiOS authentication to execute remote commands on vulnerable FortiGate and FortiProxy devices.

authentication-authorizationcommand-and-controlexploitation+3
31 year ago
CVE-2023-39362-cacti-snmp-command-injection-poc preview

CVE-2023-39362-cacti-snmp-command-injection-poc

GitHubjakabakos/cve-2023-39362-cacti-snmp-command-injection-poc

Proof-of-concept exploit for CVE-2023-39362, an authenticated command injection in Cacti's SNMP options. Includes a vulnerable Docker environment for…

command-and-controlexploitationlabs-practice+4
22 years ago
CVE-2024-12986 preview

CVE-2024-12986

GitHubaether-0/cve-2024-12986

Scanner and exploit for CVE-2024-12986, a command injection in DrayTek Gateway Devices. Includes a Bash scanner and a Python interactive shell for…

command-and-controlexploitationpenetration-testing+2
11 year ago
CVE-2024-46507 preview

CVE-2024-46507

GitHubsomchandra17/cve-2024-46507

build-script for CVE-2024-46507 and CVE-2024-46508

command-and-controleducationexploitation+6
11 year ago
Loki preview

Loki

GitHubboku7/loki

🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

command-and-controlexploitationids-ips-evasion+5
1.4k5 months ago
F5-CVE-2022-1388-Exploit preview

F5-CVE-2022-1388-Exploit

GitHubzephrfish/f5-cve-2022-1388-exploit

Exploit and check script for CVE-2022-1388, targeting F5 BIG-IP management interface to execute commands and verify vulnerability.

command-and-controlexploitationpenetration-testing+2
591 month ago
Previous12…8Next