Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
293 results
MoveIT-CVE-2023-34362-RCE preview

MoveIT-CVE-2023-34362-RCE

GitHubglen-pearson/moveit-cve-2023-34362-rce

Ruby-based exploit for CVE-2023-34362 targeting MOVEit Transfer. Automates unauthenticated RCE, creates sysadmin accounts, and deploys a remote shell…

command-and-controlexploitationpayload-development+3
2 years ago
CVE-2021-42559 preview

CVE-2021-42559

GitHubmbadanoiu/cve-2021-42559

CVE-2021-42559: Command Injection via Configurations in MITRE Caldera

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2022-26809-RCE preview

CVE-2022-26809-RCE

GitHuboppongjohn/cve-2022-26809-rce

CVE-2022-26809-RCE

command-and-controlexploitationpenetration-testing+3
4 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubxsxtw/cve-2022-26134

Python exploit script for CVE-2022-26134, a pre-authentication remote code execution vulnerability in Atlassian Confluence via OGNL injection.…

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubthetowsif/cve-2022-26134

Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubfoxyproxys/cve-2024-3400

Proof-of-concept exploit for CVE-2024-3400, a critical OS command injection vulnerability in GlobalProtect Gateway, enabling remote code execution…

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2014-6721-exploit-Shellshock preview

CVE-2014-6721-exploit-Shellshock

GitHubsagisar1/cve-2014-6721-exploit-shellshock

exploit of the Shellshock vulnerability

command-and-controlexploitationpenetration-testing+3
2 years ago
fusionpbx_rce_vulnerability preview

fusionpbx_rce_vulnerability

GitHubhoseynheydari/fusionpbx_rce_vulnerability

Chain CVE-2019-11408 – XSS in operator panel and CVE-2019-11409 – Command injection in operator panel.

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2024-10914-Exploit preview

CVE-2024-10914-Exploit

GitHubjahithoque/cve-2024-10914-exploit

Shell script exploiting CVE-2024-10914 for remote OS command injection in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L devices via cgi_user_add.

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2022-46196 preview

CVE-2022-46196

GitHubdpgg101/cve-2022-46196

Python exploit for CVE-2022-46196 targeting unauthenticated command injection in Cacti <=1.2.22. Automates version detection and reverse shell…

command-and-controlexploitationpenetration-testing+3
3 years ago
zoneminder-snapshots-rce-poc preview

zoneminder-snapshots-rce-poc

GitHubm3m0o/zoneminder-snapshots-rce-poc

This is a script written in Python that allows the exploitation of the Zoneminder's security flaw described in CVE-2023-26035.

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubg01d3nw01f/cve-2022-22963
command-and-controlexploitationpenetration-testing+3
3 years ago
covenant_rce preview

covenant_rce

GitHubzeop-cybersec/covenant_rce

PoC for Covenant C2 RCE

command-and-controlexploitationpenetration-testing+2
5 years ago
cplt preview

cplt

GitHubnavikt/cplt

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

ai-securitycommand-and-controlconfiguration-auditing+7
1215 days ago
pentest-harness preview

pentest-harness

GitHubs1n6h/pentest-harness

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

ai-securitycommand-and-controlctf+7
39316 days ago
Hexestra preview

Hexestra

GitHubabsllk/hexestra

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

ai-securitycommand-and-controlinformation-gathering+7
4217 days ago
flipper-mcp preview

flipper-mcp

GitHubroostercoopllc/flipper-mcp

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.

ai-securitybluetooth-securitycommand-and-control+9
226 months ago
reinschauer preview
Archived

reinschauer

GitHubps1337/reinschauer

it is very good

command-and-controlpost-exploitationred-teaming+2
5143 years ago
Previous1…151617Next