Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
85 results
CVE-2025-32433_Erlang-OTP_PoC preview

CVE-2025-32433_Erlang-OTP_PoC

GitHubabrewer251/cve-2025-32433_erlang-otp_poc

This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers

command-and-controlexploitationnetwork-security+3
1
1 year ago
CVE-2025-32433_PoC preview

CVE-2025-32433_PoC

GitHubodst-forge/cve-2025-32433_poc

This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers

command-and-controlexploitationnetwork-security+3
1 year ago
CVE-2022-25064 preview

CVE-2022-25064

GitHubexploitwritter/cve-2022-25064

This script exploits a remote command execution vulnerability in the TPLink WR840N router, using the configure function IPv6 protocol.

command-and-controlexploitationiot-security+3
4 years ago
Malleable-C2-Randomizer preview

Malleable-C2-Randomizer

GitHubbluscreenofjeff/malleable-c2-randomizer

A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls

command-and-controlexploit-frameworksids-ips-evasion+3
4543 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubyuvvi01/cve-2024-3400

Exploit script for CVE-2024-3400, a command injection in PAN-OS GlobalProtect, allowing unauthenticated remote code execution with root privileges.…

command-and-controlexploitationpenetration-testing+3
112 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubjoshuavanderpoll/cve-2022-30190

Python script generating Microsoft Office documents that exploit CVE-2022-30190 for remote code execution via HTML payloads, supporting custom…

command-and-controlexploitationpayload-generation+2
24 years ago
CVE-2019-0232 preview

CVE-2019-0232

GitHubdharan10/cve-2019-0232

Hi this is a revised and enhanced code for CVE-2019-0232

command-and-controlexploitationpayload-generation+3
21 year ago
CVE-2025-54123 preview

CVE-2025-54123

GitHubdavidzzo23/cve-2025-54123

Python exploit script for CVE-2025-54123 targeting Hoverfly RCE with command execution and reverse shell capabilities for authorized security testing.

command-and-controleducationexploitation+3
5 months ago
distccd_rce_CVE-2004-2687 preview

distccd_rce_CVE-2004-2687

GitHubmicheaol/distccd_rce_cve-2004-2687

Manual exploit script for CVE-2004-2687 (distccd RCE) that spawns a reverse shell via netcat without Metasploit, targeting remote hosts for…

command-and-controlexploitationpenetration-testing+3
4 months ago
CVE-2022-30525_check preview

CVE-2022-30525_check

GitHubcbk914/cve-2022-30525_check

Python script to detect CVE-2022-30525 OS command injection vulnerability in Zyxel USG FLEX devices by sending crafted HTTP requests and analyzing…

command-and-controlexploitationpenetration-testing+2
23 years ago
CVE-2025-50154-Aggressor-Script preview

CVE-2025-50154-Aggressor-Script

GitHubash1996x/cve-2025-50154-aggressor-script

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

command-and-controlctfeducation+9
111 months ago
cve-2021-31630 preview

cve-2021-31630

GitHubadibna/cve-2021-31630

This is a automation of cve-2021-31630 exploitation

command-and-controlexploitationpenetration-testing+3
12 years ago
SAP_EEM_CVE-2020-6207 preview

SAP_EEM_CVE-2020-6207

GitHubchipik/sap_eem_cve-2020-6207

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)

command-and-controleducationexploitation+4
825 years ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubthemehackers/cve-2024-10914

CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.

command-and-controleducationexploitation+4
91 year ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
16 days ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubsudoaza/cve-2022-30190

MS-MSDT Follina CVE-2022-30190 PoC document generator

command-and-controlexploitationpayload-generation+2
74 years ago
pythonprojects-CVE-2018-10933 preview

pythonprojects-CVE-2018-10933

GitHubshifa123/pythonprojects-cve-2018-10933

CVE-2018-10933

command-and-controlexploitationpenetration-testing+2
27 years ago
CVE-2019-15107 preview

CVE-2019-15107

GitHubnasrallahbaadi/cve-2019-15107

CVE-2019-15107 Webmin unauthenticated RCE

command-and-controlexploitationpenetration-testing+3
31 year ago
Previous12345Next