Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
295 results
CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2 preview

CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2

GitHubsrginebras/cve-2026-23744-rce-for-mcpjam-inspector-v1.4.2

Python exploit for CVE-2026-23744 achieving remote code execution via crafted POST requests to the /api/mcp/connect endpoint in MCPJam Inspector <=…

command-and-controlexploitationpenetration-testing+3
1
3 months ago
CVE-2020-8816 preview

CVE-2020-8816

GitHubmartinsohn/cve-2020-8816

A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing

command-and-controlexploitationpenetration-testing+3
14 years ago
CVE-2022-30525_Exploit preview

CVE-2022-30525_Exploit

GitHubarajsingh-infosec/cve-2022-30525_exploit

Exploit for CVE-2022-30525

command-and-controlexploitationpenetration-testing+3
12 years ago
bepr preview

bepr

GitHubaperocky/bepr

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

authenticationcommand-and-controlpenetration-testing+3
3 months ago
Java-Servlets-Shell preview

Java-Servlets-Shell

GitHubmbadanoiu/java-servlets-shell

JSP-less Java Servlets Backdoor inspired by https://www.redteam-pentesting.de/files/redteam-jboss.tar.gz

command-and-controlexploitationpenetration-testing+3
11 year ago
Mass-CVE-2025-29306 preview

Mass-CVE-2025-29306

GitHubmantanhacker/mass-cve-2025-29306

Mass Exploit for CVE-2025-29306

command-and-controlexploitationpenetration-testing+3
18 months ago
CVE_2024_20356 preview

CVE_2024_20356

GitHubsherllyneo/cve_2024_20356

A oxidized version of https://github.com/nettitude/CVE-2024-20356/blob/main/CVE-2024-20356.py

command-and-controlexploitationpenetration-testing+3
12 years ago
CVE-2026-34227 preview

CVE-2026-34227

GitHubskoveit/cve-2026-34227

Proof-of-concept demonstrating CORS to CSRF chain on Sliver's unauthenticated MCP interface, enabling silent interaction with C2 from any webpage.

command-and-controlexploitationred-teaming+2
16 months ago
CVE-2021-20038-SonicWall-RCE preview

CVE-2021-20038-SonicWall-RCE

GitHubvesperp/cve-2021-20038-sonicwall-rce

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

command-and-controlexploitationpenetration-testing+3
14 years ago
CVE-2025-8110-Gogs-Remote-Code-Execution preview

CVE-2025-8110-Gogs-Remote-Code-Execution

GitHubgeorge0papasotiriou/cve-2025-8110-gogs-remote-code-execution

Proof-of-concept exploit for CVE-2025-8110, a command injection vulnerability in Gogs Git hook mechanism enabling remote code execution on…

command-and-controlexploitationpenetration-testing+3
17 months ago
zoneminder_CVE-2023-26035 preview

zoneminder_CVE-2023-26035

GitHub0xfalafel/zoneminder_cve-2023-26035

Exploit for CVE-2023-26035 affecting ZoneMinder < 1.36.33 and < 1.37.33

command-and-controlexploitationpenetration-testing+3
12 years ago
CVE-2024-46658 preview

CVE-2024-46658

GitHubjackalkarlos/cve-2024-46658

Proof-of-concept exploit for a command injection vulnerability in Syrotech SY-GOPON-8OLT-L3, allowing arbitrary command execution via HTTP request…

command-and-controlexploitationpenetration-testing+3
11 year ago
CVE-2022-31499 preview

CVE-2022-31499

GitHubomarhashem123/cve-2022-31499

CVE-2022-31499 Proof of Concept

command-and-controlexploitationpenetration-testing+3
13 years ago
CVE-2024-1655 preview

CVE-2024-1655

GitHublnversed/cve-2024-1655

Authenticated RCE exploit for ASUS ExpertWiFi and RT-AX57 Go routers via command injection in splash_page_SDN.cgi. Requires a valid login token to…

command-and-controlexploitationpenetration-testing+3
12 years ago
Cobaltstrike-RCE-CVE-2022-39197 preview

Cobaltstrike-RCE-CVE-2022-39197

GitHubpurple-wl/cobaltstrike-rce-cve-2022-39197

Reproduction of CVE-2022-39197, a remote code execution vulnerability in Cobalt Strike Beacon triggered by XSS via malformed usernames, with…

command-and-controlexploitationpenetration-testing+3
14 years ago
tippa-my-tongue preview

tippa-my-tongue

GitHubj-baines/tippa-my-tongue

F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800

command-and-controlexploitationpenetration-testing+3
13 years ago
CVE-2022-30525 preview

CVE-2022-30525

GitHubfurkanzengin/cve-2022-30525

A OS Command Injection Vulnerability in the CGI Program of Zyxel

command-and-controlexploitationpenetration-testing+3
14 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubshamo0/cve-2022-1388

BIG-IP iControl REST vulnerability CVE-2022-1388 PoC

command-and-controlexploitationpenetration-testing+3
14 years ago
Previous1…131415…17Next