Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
142 results
POC_CVE-2026-41940 preview

POC_CVE-2026-41940

GitHubimbas007/poc_cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

command-and-controlexploitationpenetration-testing+3
3 months ago
CVE-2023-51126 preview

CVE-2023-51126

GitHubrisuxx/cve-2023-51126

Proof-of-concept for command injection vulnerability in FLIR AX8 camera, demonstrating remote code execution via /usr/www/res.php.

command-and-controlexploitationpenetration-testing+2
12 years ago
CVE-2026-39866 preview

CVE-2026-39866

GitHubabhayclasher/cve-2026-39866

Proof-of-concept lab demonstrating command injection in GitHub Actions workflow dispatch (CVE-2026-39866). Runs vulnerable and patched versions…

command-and-controleducationexploitation+3
4 months ago
CVE-2026-21962 preview

CVE-2026-21962

GitHubthumpbo/cve-2026-21962

Exploit script for CVE-2026-21962, enabling remote command execution on vulnerable web servers with single-target, batch, and reverse shell modes.

command-and-controlexploitationpenetration-testing+2
27 months ago
CVE-2026-0709 preview

CVE-2026-0709

GitHubsnipersmaster/cve-2026-0709

Python proof-of-concept for authenticated command injection in Hikvision wireless APs, enabling remote code execution testing with customizable…

command-and-controlexploitationpenetration-testing+3
5 months ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubelyasbassir/cve-2025-49844

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua parser, enabling remote code execution on vulnerable Redis servers.

command-and-controlexploitationremote-access-trojan+2
10 months ago
CVE-2024-12986 preview

CVE-2024-12986

GitHubaether-0/cve-2024-12986

Scanner and exploit for CVE-2024-12986, a command injection in DrayTek Gateway Devices. Includes a Bash scanner and a Python interactive shell for…

command-and-controlexploitationpenetration-testing+2
11 year ago
cve-2022-36804 preview

cve-2022-36804

GitHubjunohea/cve-2022-36804

Python exploit for CVE-2022-36804, enabling remote command execution and file transfer on vulnerable Bitbucket Server/Data Center via crafted archive…

command-and-controlexploitationpenetration-testing+2
9 days ago
Loki preview

Loki

GitHubboku7/loki

🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

command-and-controlexploitationids-ips-evasion+5
1.4k5 months ago
cve-2023-0669-simulation preview

cve-2023-0669-simulation

GitHubzakaria-laouani/cve-2023-0669-simulation

Simulation environment for CVE-2023-0669 with Docker-based attacker, vulnerable server, and listener containers. Demonstrates deserialization exploit…

command-and-controldata-exfiltrationexploitation+3
8 months ago
ShellUpload preview

ShellUpload

GitHubnu11secur1ty/shellupload

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

command-and-controlpayload-generationpenetration-testing+3
43 years ago
wp2shell preview

wp2shell

GitHubmcipekci/wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

command-and-controlexploitationpayload-development+7
151 month ago
Oracle-WebLogic-CVE-2017-10271-master preview

Oracle-WebLogic-CVE-2017-10271-master

GitHublonehand/oracle-weblogic-cve-2017-10271-master

Exploit for Oracle WebLogic CVE-2017-10271 (wls-wsat RCE bypass) with PoC scripts for remote command execution and obtaining a cmd shell on…

command-and-controlexploitationpenetration-testing+3
18 years ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubnika0x38/cve-2018-7600

A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)

command-and-controleducationexploitation+3
11 months ago
CVE-2020-14750 preview

CVE-2020-14750

GitHubpprietosanchez/cve-2020-14750

PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882

command-and-controlexploitationpenetration-testing+2
485 years ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubr0otk3r/cve-2025-3248

Scanner and exploit for CVE-2025-3248, an unauthenticated RCE in Langflow AI. Includes a vulnerability checker and a reverse shell payload generator…

command-and-controlexploitationpayload-development+5
11 year ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
PDFkit-CMD-Injection preview

PDFkit-CMD-Injection

GitHubshamo0/pdfkit-cmd-injection

CVE-2022-25765 pdfkit <0.8.6 command injection.

command-and-controlexploitationpayload-generation+2
163 years ago
Previous12…8Next