Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
94 results
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
10 days ago
xwiki_solrsearch-rce-exploit preview

xwiki_solrsearch-rce-exploit

GitHubtorjan0/xwiki_solrsearch-rce-exploit

Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.

command-and-controleducationexploitation+3
28 months ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
128 days ago
reverse-shell preview

reverse-shell

GitHublukechilds/reverse-shell

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

command-and-controlexploitationpenetration-testing+3
2.1k6 months ago
notionterm preview

notionterm

GitHubariary/notionterm

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

command-and-controlexploitationpayload-generation+3
1383 years ago
react2shell-poc preview

react2shell-poc

GitHubp3ta00/react2shell-poc

CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.

command-and-controleducationexploitation+5
92 months ago
CVE-2023-33538 preview

CVE-2023-33538

GitHubexplxx/cve-2023-33538

Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability

command-and-controleducationexploitation+5
11 year ago
CVE-2022-44877-white-box preview

CVE-2022-44877-white-box

GitHubhotpotcookie/cve-2022-44877-white-box

Red Team utilities for setting up CWP CentOS 7 payload & reverse shell (Red Team 9 - CW2023)

command-and-controlexploitationids-ips-evasion+6
62 years ago
OpenShell preview

OpenShell

GitHubiss4cf0ng/openshell

Lightweight Go-based reverse shell management server with a web GUI for interactive shell sessions, session management, and multi-tab terminal…

command-and-controlpenetration-testingred-teaming+3
245 months ago
IS preview

IS

GitHubsadz1d/is

Metasploit-based exploit launcher for CVE-2017-7494 (Samba) with automated payload delivery and reverse shell session management.

command-and-controlexploitationpayload-generation+4
1 month ago
webmin_1.920 preview

webmin_1.920

GitHubhadrian3689/webmin_1.920

CVE-2019-15107 Webmin 1.920 RCE

command-and-controlexploitationpenetration-testing+3
3 years ago
CVE-2024-36401-poc preview

CVE-2024-36401-poc

GitHubdelt-a/cve-2024-36401-poc

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

command-and-controlexploitationpenetration-testing+4
2 months ago
HTTP-Shell preview

HTTP-Shell

GitHubjoelgmsec/http-shell

Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

command-and-controlpayload-generationpenetration-testing+2
24315 days ago
Shell3er preview

Shell3er

GitHubyehia-mamdouh/shell3er

PowerShell-based reverse shell with background task execution, file transfer, and dual persistence mechanisms via registry and startup folder for red…

command-and-controlpayload-generationpersistence-mechanisms+3
813 years ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubdynamo2k1/cve-2026-33017

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

command-and-controlexploitationpayload-generation+4
28 days ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
9 days ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubozcanpng/cve-2026-23744

Unauthenticated remote code execution proof-of-concept for CVE-2026-23744 targeting MCPJam Inspector. Generates crafted MCP serverConfig payloads to…

command-and-controlexploitationpayload-generation+5
1 month ago
RevShell preview

RevShell

GitHubdragon56yt/revshell

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

command-and-controldata-exfiltrationeducation+8
22 months ago
Previous123456Next