Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
CVE-2026-33017 preview

CVE-2026-33017

GitHubmaxprog-svg/cve-2026-33017

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

command-and-controlexploitationreconnaissance+3
28 days ago
POC_CVE-2026-41940 preview

POC_CVE-2026-41940

GitHubimbas007/poc_cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

command-and-controlexploitationpenetration-testing+3
5 months ago
ls-poc preview

ls-poc

GitHubtruekas/ls-poc

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

command-and-controlexploitationpayload-development+3
135 months ago
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
265 months ago
CVE-2025-64155-hunter preview

CVE-2025-64155-hunter

GitHubpurehate/cve-2025-64155-hunter

CVE-2025-64155-hunter

command-and-controlexploitationpenetration-testing+3
7 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xsj/cve-2025-55182

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

command-and-controlexploitationpenetration-testing+3
17 months ago
Torito-R2S preview

Torito-R2S

GitHubtoritoio/torito-r2s

Torito React2Shell Scanner & Exploit Tool (CVE-2025-55182 / 66478)

command-and-controlexploitationpenetration-testing+4
49 months ago
CVE-2025-4428 preview

CVE-2025-4428

GitHubxie-22/cve-2025-4428

Ivanti EPMM Pre-Auth RCE Chain

command-and-controlexploitationpenetration-testing+3
411 months ago
CVE-2025-24893-XWiki-RCE preview

CVE-2025-24893-XWiki-RCE

GitHubhex00-0x4/cve-2025-24893-xwiki-rce

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine…

command-and-controlexploitationpenetration-testing+3
61 year ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubimbas007/cve-2025-3248

Python-based exploit for CVE-2025-3248 enabling remote code execution on vulnerable Langflow instances. Supports single URL and bulk scanning with…

command-and-controlexploitationpenetration-testing+3
21 year ago
CVE-2024-36401_Geoserver_RCE_POC preview

CVE-2024-36401_Geoserver_RCE_POC

GitHubamoy6228/cve-2024-36401_geoserver_rce_poc

本脚本是针对 GeoServer 的远程代码执行漏洞(CVE-2024-36401)开发的 PoC(Proof of Concept)探测工具。该漏洞允许攻击者通过构造特定请求,在目标服务器上执行任意命令。

command-and-controlexploitationpenetration-testing+3
21 year ago
ConfluentPwn preview

ConfluentPwn

GitHubredhuntlabs/confluentpwn

Atlassian confluence unauthenticated ONGL injection remote code execution scanner (CVE-2022-26134).

command-and-controlexploitationpenetration-testing+3
121 year ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubaratane/cve-2024-9474

Palo Alto RCE Vuln

command-and-controlexploitationpenetration-testing+3
11 year ago
CVE-2024-27348 preview

CVE-2024-27348

GitHubzeyad-azima/cve-2024-27348

Apache HugeGraph Server RCE Scanner ( CVE-2024-27348 )

command-and-controlexploitationpenetration-testing+3
602 years ago
CVE-2024-29895.py preview

CVE-2024-29895.py

GitHubticofookfook/cve-2024-29895.py

Python exploit for Cacti RCE (CVE-2024-29895) via command injection in cmd_realtime.php. Includes reconnaissance dorks for Google, Shodan, and FOFA.

command-and-controlexploitationreconnaissance+2
2 years ago
CVE-2024-29895-CactiRCE-PoC preview

CVE-2024-29895-CactiRCE-PoC

GitHubstuub/cve-2024-29895-cactirce-poc

CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds

command-and-controlexploitationpenetration-testing+3
212 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubandrelia-hacks/cve-2024-3400

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

command-and-controlexploitationpenetration-testing+3
2 years ago
primefaces preview

primefaces

GitHubjam620/primefaces

Explotación CVE-2017-1000486

command-and-controlexploitationpenetration-testing+4
2 years ago
Previous12Next