Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
910 results
cve-2025-11953-vulnerability-demo preview

cve-2025-11953-vulnerability-demo

GitHubsaidbenaissa/cve-2025-11953-vulnerability-demo

CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits…

command-and-controleducationexploitation+3
4
11 months ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
22 months ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
2 months ago
abyss-c2 preview

abyss-c2

GitHubflags-alt/abyss-c2

Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning,…

command-and-controleducationexploit-frameworks+7
24 months ago
CVE-2026-67595 preview

CVE-2026-67595

GitHubilhomjonr/cve-2026-67595

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

command-and-controlmalware-analysisstatic-analysis+4
1 month ago
CVE-2023-1671 preview

CVE-2023-1671

GitHubohnonoyesyes/cve-2023-1671

Pre-Auth RCE in Sophos Web Appliance

command-and-controlexploitationpenetration-testing+3
33 years ago
CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC preview

CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC

GitHubcerberusmrxi/cve-2026-57588-nessus-xml-import-sql-injection-poc

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…

command-and-controldatabase-securitydata-exfiltration+7
12 months ago
gotigate preview

gotigate

GitHubgustavorobertux/gotigate

Go-based exploit for CVE-2022-40684 targeting Fortinet FortiGate devices. Automates authentication bypass to gain administrative access via the web…

command-and-controlexploitationpenetration-testing+3
23 years ago
CVE-2026-2256-PoC preview

CVE-2026-2256-PoC

GitHubitamar-yochpaz/cve-2026-2256-poc

Proof-of-concept demonstrating a command injection vulnerability in MS-Agent Shell tool, enabling arbitrary command execution and reverse shell via…

command-and-controlexploitationpenetration-testing+2
27 months ago
Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit preview

Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit

GitHub0x00phantom-hat/hoverfly-1.11.3-rce-cve-2025-54123-exploit

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

command-and-controleducationexploitation+6
14 months ago
coolify-cve-2025-66209-66213 preview

coolify-cve-2025-66209-66213

GitHub0xrakan/coolify-cve-2025-66209-66213

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213

cloud-securitycommand-and-controlcontainer-escape+3
19 months ago
CVE-2023-38829-NETIS-WF2409E preview

CVE-2023-38829-NETIS-WF2409E

GitHubadhikara13/cve-2023-38829-netis-wf2409e

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

command-and-controleducationexploitation+3
13 years ago
cve-2018-1335 preview

cve-2018-1335

GitHubcanumay/cve-2018-1335

CENG 325 - Principles of Information Security And Privacy

command-and-controleducationexploitation+3
15 years ago
CVE-2007-2447 preview

CVE-2007-2447

GitHubabdulsaabir/cve-2007-2447

Proof-of-concept exploit for Samba usermap script remote command execution (CVE-2007-2447), with reverse shell capability for controlled lab testing…

command-and-controleducationexploitation+4
19 months ago
CVE-2022-41080 preview

CVE-2022-41080

GitHubohnonoyesyes/cve-2022-41080

Proof-of-concept exploit for CVE-2022-41080 (OWASSRF) enabling remote code execution through Microsoft Exchange Outlook Web Access, bypassing…

command-and-controlexploitationpenetration-testing+3
13 years ago
CVE-2021-32305-websvn-2.6.0 preview

CVE-2021-32305-websvn-2.6.0

GitHubfredbrave/cve-2021-32305-websvn-2.6.0

This is a exploit of CVE-2021-32305 a web vulnerability to command injection on search.php path, this exploit allows execute commands.

command-and-controlexploitationpenetration-testing+2
12 years ago
react2shell-interactive preview

react2shell-interactive

GitHubnathanj60/react2shell-interactive

CVE-2025-55182 Interactive PoC - React Server Components RCE - Educational Security Research

command-and-controleducationexploitation+5
10 months ago
CVE-2021-36260-hikvision preview

CVE-2021-36260-hikvision

GitHubshubtheone/cve-2021-36260-hikvision

Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command…

command-and-controlexploitationiot-security+3
8 months ago
Previous1…345…51Next