Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
CVE-2024-36401-poc preview

CVE-2024-36401-poc

GitHubdelt-a/cve-2024-36401-poc

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

command-and-controlexploitationpenetration-testing+4
3 months ago
cve-2025-8110-GOGS-RCE preview

cve-2025-8110-GOGS-RCE

GitHubkayl22/cve-2025-8110-gogs-rce

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

command-and-controlexploitationpayload-development+4
45 months ago
CVE-2019-15107 preview

CVE-2019-15107

GitHubbayazid-bit/cve-2019-15107

Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)

command-and-controlexploitationpayload-generation+3
5 months ago
HikvisionExploiter preview

HikvisionExploiter

GitHubtamim1089/hikvisionexploiter

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

command-and-controlencryption-decryption-toolsexploitation+8
3869 months ago
rConfig_rce preview

rConfig_rce

GitHubcspanias/rconfig_rce

Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)

command-and-controleducationexploitation+4
1 year ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubkrill-x7/cve-2011-2523

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

command-and-controlexploitationpayload-generation+3
11 year ago
CVE-2025-24016-Wazuh-Remote-Code-Execution-RCE-PoC preview

CVE-2025-24016-Wazuh-Remote-Code-Execution-RCE-PoC

GitHubcybersecplayground/cve-2025-24016-wazuh-remote-code-execution-rce-poc

A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects…

command-and-controlexploitationpayload-development+4
21 year ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
CVE-2023-0830 preview

CVE-2023-0830

GitHubxbz0n/cve-2023-0830

Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.

command-and-controlexploitationpayload-generation+3
11 year ago
vsftpd-backdoor preview

vsftpd-backdoor

GitHublychi3/vsftpd-backdoor

Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523

command-and-controlexploitationpayload-generation+3
1 year ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubimnotcha0s/cve-2024-10914

Python-based exploit for CVE-2024-10914 targeting command injection in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L NAS devices.

command-and-controlexploitationpenetration-testing+2
151 year ago
FuguHub-8.4-Authenticated-RCE-CVE-2024-27697 preview

FuguHub-8.4-Authenticated-RCE-CVE-2024-27697

GitHubsanjindedic/fuguhub-8.4-authenticated-rce-cve-2024-27697

Arbitrary Code Execution on FuguHub 8.4

command-and-controlexploitationpayload-development+5
102 years ago
SnitchDNS preview

SnitchDNS

GitHubctxis/snitchdns

Database Driven DNS Server with a Web UI

command-and-controldata-exfiltrationdns-analysis+7
2442 years ago
dark-doh preview

dark-doh

GitHubdarksh3llru/dark-doh

Covert file-transfer tool using DNS-over-HTTPS: encodes payload chunks in TXT records, applies XOR obfuscation, and can execute shellcode for…

command-and-controldata-exfiltrationred-teaming
202 years ago
Veil preview
Archived

Veil

GitHubveil-framework/veil

Veil 3.1.X (Check version info in Veil at runtime)

command-and-controlexploit-frameworkspayload-generation+2
4.2k2 years ago
CVE-2022-46196 preview

CVE-2022-46196

GitHubdpgg101/cve-2022-46196

Python exploit for CVE-2022-46196 targeting unauthenticated command injection in Cacti <=1.2.22. Automates version detection and reverse shell…

command-and-controlexploitationpenetration-testing+3
3 years ago
wmiexec-RegOut preview
Archived

wmiexec-RegOut

GitHubxiaolichan/wmiexec-regout

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

command-and-controlids-ips-evasionlateral-movement+3
2753 years ago
CVE-2021-41730 preview

CVE-2021-41730

GitHubyezeting/cve-2021-41730

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

command-and-controlembedded-systems-securityexploitation+5
4 years ago
Previous12Next