Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
SSTImap preview

SSTImap

GitHubvladko312/sstimap

Automatic SSTI detection tool with interactive interface

code-analysiscommand-and-controldynamic-code-analysis+6
1.7k1 month ago
iodine preview

iodine

GitHubyarrick/iodine

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

command-and-controldata-exfiltrationids-ips-evasion+4
8.0k4 days ago
CVE-2022-36446-Webmin-Software-Package-Updates-RCE preview

CVE-2022-36446-Webmin-Software-Package-Updates-RCE

GitHubp0dalirius/cve-2022-36446-webmin-software-package-updates-rce

A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.

command-and-controlexploitationpenetration-testing+3
1151 year ago
CVE-2023-28343 preview

CVE-2023-28343

GitHubgobysec/cve-2023-28343

Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)

command-and-controlexploitationpenetration-testing+3
63 years ago
CTT-Mailpit-RCE-v1.0---Temporal-Resonance-Mail-Server-Takeover preview

CTT-Mailpit-RCE-v1.0---Temporal-Resonance-Mail-Server-Takeover

GitHubsimoesctt/ctt-mailpit-rce-v1.0---temporal-resonance-mail-server-takeover

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

command-and-controlexploitationmalware-analysis+5
8 months ago
CVE-2025-67888 preview

CVE-2025-67888

GitHubreewardius/cve-2025-67888

Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link:

command-and-controlexploitationpenetration-testing+2
9 months ago
cve_2025_20265 preview

cve_2025_20265

GitHubsaruman9/cve_2025_20265

PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubihebski/cve-2024-3400

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

command-and-controlexploitationpenetration-testing+2
342 years ago
CVE-2023-38646 preview

CVE-2023-38646

GitHubpyr0sec/cve-2023-38646

Exploit script for Pre-Auth RCE in Metabase (CVE-2023-38646)

command-and-controlexploitationpenetration-testing+3
112 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubadanikamal/cve-2024-3400

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

command-and-controlexploitationnetwork-security+3
82 years ago
CVE-2022-36446 preview

CVE-2022-36446

GitHubemirpolatt/cve-2022-36446

CVE-2022-36446 - Webmin 1.996 Remote Code Execution

command-and-controlexploitationpenetration-testing+3
34 years ago
CVE-2024-0012 preview

CVE-2024-0012

GitHub0xjessie21/cve-2024-0012

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

authenticationcommand-and-controlexploitation+3
31 year ago
FreePBX-CVE-2025-57819 preview

FreePBX-CVE-2025-57819

GitHubyuvrajshad/freepbx-cve-2025-57819

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

command-and-controlexploitationpayload-development+5
13 months ago
Eaton-UPS-Companion-Exploit preview

Eaton-UPS-Companion-Exploit

GitHubravss/eaton-ups-companion-exploit

This repository details CVE-2020-6650, a vulnerability I discovered within Eaton's UPS Companion. All users should upgrade to v1.06 immediately or…

command-and-controlexploitationpayload-development+5
16 years ago
CVE-2021-3060 preview

CVE-2021-3060

GitHubanmolksachan/cve-2021-3060

CVE-2021-3060

command-and-controlexploitationpayload-development+3
3 years ago
CVE-2021-40222 preview

CVE-2021-40222

GitHubasang17/cve-2021-40222

Remote Code Execution at Rittal

command-and-controlexploitationpenetration-testing+3
5 years ago
CVE-2022-23935 preview

CVE-2022-23935

GitHubantisecc/cve-2022-23935

Exploit for CVE-2022-23935, a command injection vulnerability in Exiftool versions prior to 12.38, allowing arbitrary command execution via crafted…

binary-exploitationcommand-and-controlexploitation+3
3 years ago
bunitu_tests preview

bunitu_tests

GitHubhasherezade/bunitu_tests

Scripts for communication with Bunitu Trojan C&Cs

command-and-controlmalware-analysispenetration-testing+2
1910 years ago
Previous12Next