Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
142 results
CVE-2024-7029 preview

CVE-2024-7029

GitHubgeniuszly/cve-2024-7029

PoC exploit for CVE-2024-7029 in AvTech devices. Scans for vulnerable targets and provides an interactive remote shell for command execution with…

command-and-controlexploitationpenetration-testing+4
9
1 year ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubianxtianxt/cve-2019-19781

Shell-based remote code execution exploit targeting CVE-2019-19781 in Citrix Application Delivery Controller and Citrix Gateway. Executes arbitrary…

command-and-controlexploitationpenetration-testing+3
76 years ago
CVE-2026-10523-Ivanti-sentry preview

CVE-2026-10523-Ivanti-sentry

GitHubgagaltotal/cve-2026-10523-ivanti-sentry

Proof-of-concept detection tool for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520, CVE-2026-10523).…

authenticationcommand-and-controlexploitation+3
32 months ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubzain3311/cve-2025-49844

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

command-and-controlexploitationpayload-development+3
26 days ago
CVE-2022-26134_Behinder_MemShell preview

CVE-2022-26134_Behinder_MemShell

GitHubmaskcybersecurityteam/cve-2022-26134_behinder_memshell

Java-based exploit for CVE-2022-26134 that deploys a Behinder memory shell on vulnerable Atlassian Confluence servers for remote command execution.

command-and-controlexploitationpayload-generation+3
93 years ago
CVE-2019-16278 preview

CVE-2019-16278

GitHubianxtianxt/cve-2019-16278

Python exploit script for CVE-2019-16278, a remote command execution vulnerability in Nostromo httpd. Executes arbitrary commands on vulnerable…

command-and-controlexploitationpenetration-testing+2
36 years ago
CVE-2017-12636 preview

CVE-2017-12636

GitHubmoayadalmalat/cve-2017-12636

Exploit for CouchDB arbitrary command execution vulnerability (CVE-2017-12636). Automates remote code execution against vulnerable CouchDB instances.

command-and-controlexploitationpayload-generation+2
38 years ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
livewire-honeypot preview

livewire-honeypot

GitHubhelgesverre/livewire-honeypot

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

command-and-controldynamic-analysis-sandboxingexploitation+6
53 months ago
ShellUpload preview

ShellUpload

GitHubnu11secur1ty/shellupload

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

command-and-controlpayload-generationpenetration-testing+3
43 years ago
cve-2022-33891 preview

cve-2022-33891

GitHubakbartrilaksana/cve-2022-33891

Python proof-of-concept for Apache Spark Shell Command Injection (CVE-2022-33891), featuring sleep-based detection, interactive command execution,…

command-and-controlexploitationpayload-generation+3
37 months ago
cve-2026-23744 preview

cve-2026-23744

GitHubrohit-sundar/cve-2026-23744

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated RCE in MCPJam Inspector. Provides reverse shell and command execution via a…

command-and-controleducationexploitation+6
2 months ago
CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE- preview

CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE-

GitHubfevar54/cve-2026-20253-splunk-enterprise-pre-auth-rce-

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

command-and-controlexploitationpayload-development+5
2 months ago
StrutsShell preview

StrutsShell

GitHubfalcon-lnhg/strutsshell

Interactive command-line shell for exploiting Apache Struts CVE-2017-5638. Automates HTTP/HTTPS exploitation with real-time shell interaction on…

command-and-controlexploitationpenetration-testing+3
39 years ago
CVE-2026-48732-poc preview

CVE-2026-48732-poc

GitHubsaku0512/cve-2026-48732-poc

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

command-and-controleducationexploitation+3
2 months ago
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

binary-analysiscommand-and-controlembedded-systems-security+7
21 year ago
CVE-2026-34156-NocoBase-Sandbox-Escape-via-Workflow-Execution-Vulnerability- preview

CVE-2026-34156-NocoBase-Sandbox-Escape-via-Workflow-Execution-Vulnerability-

GitHubdhananjayasj/cve-2026-34156-nocobase-sandbox-escape-via-workflow-execution-vulnerability-

Authenticated RCE exploit for NocoBase workflow engine sandbox escape (CVE-2026-34156). Executes arbitrary system commands via crafted workflow…

command-and-controlexploitationpenetration-testing+3
2 months ago
cve-2022-26134 preview

cve-2022-26134

GitHubf4yd4-s3c/cve-2022-26134

Python exploit for Atlassian Confluence CVE-2022-26134 OGNL injection vulnerability enabling unauthenticated remote code execution on vulnerable…

command-and-controlexploitationpenetration-testing+2
21 year ago
Previous123…8Next