Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
browser-crash-tool preview

browser-crash-tool

GitHublyonzon2/browser-crash-tool

Automated browser crash tool exploiting CVE-2020-27950 (iOS WebKit) via Metasploit and ngrok. Generates public malicious URL for controlled…

command-and-controleducationexploitation+4
5
1 year ago
CVE-2019-0232 preview

CVE-2019-0232

GitHubjorge2rubio/cve-2019-0232

Automated exploitation tool for CVE-2019-0232 (Apache Tomcat CGI RCE) with command execution and reverse shell modes, automatic URL encoding, and…

command-and-controlexploitationpayload-generation+3
110 months ago
CVE-2026-5027-Langflow preview

CVE-2026-5027-Langflow

GitHublayer-6/cve-2026-5027-langflow

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

command-and-controlexploitationpayload-development+8
4 months ago
mcpExec preview

mcpExec

GitHubdaemoncibsec/mcpexec

POC for CVE-2026-23744 for a python revshell

command-and-controlexploitationpayload-generation+3
1 month ago
Webmin-1.580---file-show.cgi-Manual-Remote-Command-Execution-Non-Metasploit- preview

Webmin-1.580---file-show.cgi-Manual-Remote-Command-Execution-Non-Metasploit-

GitHubmarinovharisan/webmin-1.580---file-show.cgi-manual-remote-command-execution-non-metasploit-

Manual, non-Metasploit authenticated Remote Code Execution (RCE) exploit via the browser URL bar for Webmin 1.580 (CVE-2012-2982)

command-and-controlexploitationpenetration-testing+3
4 months ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubamitlttwo/cve-2022-1388

Python-based exploit for CVE-2022-1388, an F5 BIG-IP iControl REST authentication bypass leading to remote code execution. Supports single URL,…

command-and-controlexploitationpenetration-testing+3
13 years ago
CVE-2022-30525 preview

CVE-2022-30525

GitHubhenry4e36/cve-2022-30525

Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)

command-and-controlexploitationpenetration-testing+3
224 years ago
CVE-2024-36401 preview

CVE-2024-36401

GitHubniuwoo/cve-2024-36401

POC

command-and-controlexploitationremote-access-tool+2
42 years ago
CVE-2021-26084 preview

CVE-2021-26084

GitHubjun-5heng/cve-2021-26084

confluence远程代码执行RCE / Code By:Jun_sheng

command-and-controlexploitationpenetration-testing+3
14 years ago
cve-2025-3248 preview

cve-2025-3248

GitHubbambooqj/cve-2025-3248

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

command-and-controlexploitationpenetration-testing+3
111 months ago
F5-BIG-IP-exploit preview

F5-BIG-IP-exploit

GitHubsashka3076/f5-big-ip-exploit

CVE-2022-1388

command-and-controlexploitationremote-access-tool+2
4 years ago
CVE-2019-3396-Memshell-for-Behinder preview

CVE-2019-3396-Memshell-for-Behinder

GitHubavento/cve-2019-3396-memshell-for-behinder

CVE-2019-3396 Memshell for Behinder

command-and-controlexploitationpayload-development+3
22 years ago
CVE-2025-33053-Proof-Of-Concept preview

CVE-2025-33053-Proof-Of-Concept

GitHubdevbuihieu/cve-2025-33053-proof-of-concept

CVE-2025-33053 Proof Of Concept (PoC)

command-and-controlexploitationlateral-movement+6
621 year ago
CVE-2018-14714-POC preview

CVE-2018-14714-POC

GitHubsunn1day/cve-2018-14714-poc

CVE-2018-14714 PoC RCE

command-and-controlexploitationiot-security+3
94 years ago
CVE-2021-46422 preview

CVE-2021-46422

GitHubkelemaoya/cve-2021-46422

PoC exploit for CVE-2021-46422, an OS command injection vulnerability in Korean wireless routers. Includes a Python script for single or batch URL…

command-and-controlexploitationpenetration-testing+2
3 years ago
CVE-2015-1427 preview

CVE-2015-1427

GitHubxpgdgit/cve-2015-1427

Exploit for CVE-2015-1427 with single URL, batch file, and custom command execution capabilities for testing Elasticsearch Groovy sandbox bypass…

command-and-controlexploitationpenetration-testing+2
4 years ago
CVE-2014-6287 preview

CVE-2014-6287

GitHub10cks/cve-2014-6287

Rejetto http File Server 2.3.x (Reverse shell)

command-and-controlexploitationpayload-generation+3
3 years ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubahmadf77/cve-2026-23744

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

command-and-controlexploitationpayload-development+3
6 months ago
Previous1234Next