Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
26
4 months ago
CVE-2022-36804-PoC-Exploit preview

CVE-2022-36804-PoC-Exploit

GitHubbenjaminhays/cve-2022-36804-poc-exploit

Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

command-and-controlexploitationpenetration-testing+3
162 years ago
ls-poc preview

ls-poc

GitHubtruekas/ls-poc

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

command-and-controlexploitationpayload-development+3
144 months ago
F5-BIG-IP-RCE-CVE-2022-1388 preview

F5-BIG-IP-RCE-CVE-2022-1388

GitHubangus-team/f5-big-ip-rce-cve-2022-1388

Multi-threaded Python scanner for CVE-2022-1388, an F5 BIG-IP remote code execution vulnerability. Supports single URL and batch file input, with…

command-and-controlexploitationpenetration-testing+3
54 years ago
Confluence-CVE-2022-26134 preview

Confluence-CVE-2022-26134

GitHuby000o/confluence-cve-2022-26134

Proof-of-concept exploit for CVE-2022-26134 in Confluence Server, using OGNL injection to execute commands via crafted HTTP requests.

command-and-controlexploitationreconnaissance+2
44 years ago
CVE-2020-7961-Mass preview

CVE-2020-7961-Mass

GitHubcrackercat/cve-2020-7961-mass

CVE-2020–7961 Mass exploit for Script Kiddies

command-and-controlexploitationreconnaissance+2
25 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubdevengpk/cve-2022-1388

Exploit and mass-check script for CVE-2022-1388 targeting F5 BIG-IP iControl REST unauthenticated remote command execution. Supports single host,…

command-and-controlexploitationpenetration-testing+3
23 years ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubimbas007/cve-2025-3248

Python-based exploit for CVE-2025-3248 enabling remote code execution on vulnerable Langflow instances. Supports single URL and bulk scanning with…

command-and-controlexploitationpenetration-testing+3
21 year ago
POC_CVE-2026-41940 preview

POC_CVE-2026-41940

GitHubimbas007/poc_cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

command-and-controlexploitationpenetration-testing+3
4 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xsj/cve-2025-55182

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

command-and-controlexploitationpenetration-testing+3
17 months ago
CVE-2022-22954-PoC preview

CVE-2022-22954-PoC

GitHubamit-pathak009/cve-2022-22954-poc

Proof-of-concept exploit for CVE-2022-22954, a VMware Workspace ONE Access and Identity Manager RCE via SSTI. Supports manual, file-based, and…

command-and-controlexploitationreconnaissance+2
4 years ago
Apache-Struts preview

Apache-Struts

GitHubc002/apache-struts

Python-based exploit for Apache Struts CVE-2017-5638 with single URL and batch scanning modes, vulnerability checking, and Nmap reconnaissance…

command-and-controlexploitationpenetration-testing+3
9 years ago
CVE-2022-36804-ReverseShell preview

CVE-2022-36804-ReverseShell

GitHub0xeleven/cve-2022-36804-reverseshell

PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

command-and-controlexploitationpenetration-testing+3
3 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubli8u99/cve-2022-1388

Exploit script for CVE-2022-1388 targeting F5 BIG-IP pre-auth RCE via /mgmt/tm/util/bash endpoint. Includes detection, version scanning, and…

command-and-controlexploitationpenetration-testing+3
4 years ago
Juniper-exploit-CVE-2023-36845 preview

Juniper-exploit-CVE-2023-36845

GitHubcharondefalt/juniper-exploit-cve-2023-36845

Exploit for CVE-2023-36845, a PHP environment variable manipulation vulnerability in Juniper SRX/EX, enabling unauthenticated remote code execution…

command-and-controlexploitationpayload-development+3
2 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubandrelia-hacks/cve-2024-3400

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2024-29895.py preview

CVE-2024-29895.py

GitHubticofookfook/cve-2024-29895.py

Python exploit for Cacti RCE (CVE-2024-29895) via command injection in cmd_realtime.php. Includes reconnaissance dorks for Google, Shodan, and FOFA.

command-and-controlexploitationreconnaissance+2
2 years ago
LOG4J-CVE-2021-44228 preview
Archived

LOG4J-CVE-2021-44228

GitHubsumitpathania03/log4j-cve-2021-44228

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including vulnerable server setup, exploit…

command-and-controlexploitationpacket-sniffing-analysis+3
3 years ago
Previous12Next