Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
880 results
CVE-2023-38743 preview

CVE-2023-38743

GitHubpetrusviet/cve-2023-38743

ManageEngine ADManager Command Injection

command-and-controlexploitationpenetration-testing+2
112 years ago
firepwner preview

firepwner

GitHubmattimustang/firepwner

Exploit for CVE-2015-6357 Cisco FireSIGHT Management Center Certificate Validation Vulnerability

command-and-controldns-analysisexploitation+4
610 years ago
CVE-2020-8813-Cacti-RCE-in-graph_realtime preview

CVE-2020-8813-Cacti-RCE-in-graph_realtime

GitHubp0dalirius/cve-2020-8813-cacti-rce-in-graph_realtime

CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8

command-and-controlexploitationpenetration-testing+2
71 year ago
njutils preview

njutils

GitHubseep1959/njutils

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

command-and-controlpayload-developmentpenetration-testing+3
78 years ago
flask_heroku_redirector preview

flask_heroku_redirector

GitHubkillswitch-gui/flask_heroku_redirector

flask heroku C2 redirector template

cloud-securitycommand-and-controlpenetration-testing+3
119 years ago
CVE-2021-38817-Remote-OS-Command-Injection preview

CVE-2021-38817-Remote-OS-Command-Injection

GitHubhuskyhacks/cve-2021-38817-remote-os-command-injection

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

command-and-controlexploitationpayload-development+3
93 years ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubadhikara13/cve-2023-27350

Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking

command-and-controlexploitationpayload-development+3
93 years ago
CVE-2023-0669 preview

CVE-2023-0669

GitHubavento/cve-2023-0669

GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)

command-and-controlexploitationpayload-development+3
83 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubpayatu/cve-2017-5638

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

command-and-controlexploitationpenetration-testing+3
89 years ago
Webmin_1.890-POC preview

Webmin_1.890-POC

GitHubn0obit4/webmin_1.890-poc

CVE-2019-15107 exploit

command-and-controlexploitationpenetration-testing+3
75 years ago
CVE-2021-22893 preview

CVE-2021-22893

GitHuborangmuda/cve-2021-22893

Proof On Concept — Pulse Secure CVE-2021-22893

command-and-controlexploitationpenetration-testing+3
74 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubadanikamal/cve-2024-3400

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

command-and-controlexploitationnetwork-security+3
82 years ago
CVE-2023-30258-magnus-billing-v7-exploit preview

CVE-2023-30258-magnus-billing-v7-exploit

GitHubtinashelorenzi/cve-2023-30258-magnus-billing-v7-exploit

Automated Python exploit for CVE-2023-30258, a command injection in Magnus Billing System v7. Sends crafted GET request to icepay.php to execute…

command-and-controlexploitationpenetration-testing+3
81 year ago
CVE-202122986-EXP preview

CVE-202122986-EXP

GitHubyaunsky/cve-202122986-exp

F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用

command-and-controlexploitationpenetration-testing+2
85 years ago
CVE-2020-11978 preview

CVE-2020-11978

GitHubpberba/cve-2020-11978

PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11

command-and-controlexploitationpenetration-testing+2
85 years ago
Havoc-C2-SSRF-to-RCE preview

Havoc-C2-SSRF-to-RCE

GitHubsebr-dev/havoc-c2-ssrf-to-rce

This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE exploit from @hyperreality. This exploit executes…

command-and-controlexploitationpenetration-testing+3
91 year ago
CVE-2020-14882 preview

CVE-2020-14882

GitHubqmf0c3uk/cve-2020-14882

Python exploit for CVE-2020-14882 targeting Oracle WebLogic servers with remote command execution via URL scanning and batch file processing.

command-and-controlexploitationpenetration-testing+2
75 years ago
flask_pythonanywhere_redirector preview

flask_pythonanywhere_redirector

GitHubkillswitch-gui/flask_pythonanywhere_redirector

flask pythonanywhere C2 redirector template

command-and-controlpayload-developmentpenetration-testing+2
89 years ago
Previous1…161718…49Next