Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
282 results
CVE-2025-55182-GodzillaMemoryShell preview

CVE-2025-55182-GodzillaMemoryShell

GitHubbeichendream/cve-2025-55182-godzillamemoryshell

Exploit script for CVE-2025-55182 that deploys a Godzilla memory shell on vulnerable web servers, with support for proxy and encoding options.

command-and-controlexploitationpayload-generation+3
108
9 months ago
php_reverse_shell preview

php_reverse_shell

GitHubh3x0v3rl0rd/php_reverse_shell

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

command-and-controlpenetration-testingpost-exploitation+3
5 years ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubahmadf77/cve-2026-23744

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

command-and-controlexploitationpayload-development+3
5 months ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
1 month ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubr0otk3r/cve-2022-1388

Python exploit for CVE-2022-1388, an unauthenticated remote command execution vulnerability in F5 BIG-IP iControl REST. Supports single commands and…

command-and-controlexploitationpenetration-testing+3
1 year ago
webmin_1.920 preview

webmin_1.920

GitHubhadrian3689/webmin_1.920

Python3 exploit for CVE-2019-15107 Webmin 1.920 unauthenticated remote command execution, delivering reverse shells or firewall-evading…

command-and-controlexploitationpenetration-testing+3
4 years ago
CVE-2022-25226 preview

CVE-2022-25226

GitHubkrill-x7/cve-2022-25226

Python exploit script for ThinVNC 1.0b1 authentication bypass (CVE-2022-25226) that chains unauthenticated /cmd endpoint access with AMSI bypass and…

authenticationcommand-and-controleducation+4
11 year ago
ShellUpload preview

ShellUpload

GitHubnu11secur1ty/shellupload

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

command-and-controlpayload-generationpenetration-testing+3
43 years ago
CVE-2025-24893 preview

CVE-2025-24893

GitHubandwati/cve-2025-24893

Python exploit for CVE-2025-24893 that executes a reverse shell on vulnerable web applications, with shell upgrade instructions.

command-and-controlexploitationpayload-generation+3
1 year ago
b374k preview

b374k

GitHubb374k/b374k

PHP Webshell with handy features

command-and-controldatabase-securitypenetration-testing+2
2.7k3 years ago
CVE-2025-27590 preview

CVE-2025-27590

GitHubfatkz/cve-2025-27590

Proof-of-concept exploit for CVE-2025-27590, a command injection vulnerability in multipart form uploads enabling remote shell execution and SSH key…

command-and-controlexploitationpenetration-testing+2
11 year ago
cve-2021-31630 preview

cve-2021-31630

GitHubadibna/cve-2021-31630

This is a automation of cve-2021-31630 exploitation

command-and-controlexploitationpenetration-testing+3
12 years ago
CVE-2026-21962 preview

CVE-2026-21962

GitHubthumpbo/cve-2026-21962

Exploit script for CVE-2026-21962, enabling remote command execution on vulnerable web servers with single-target, batch, and reverse shell modes.

command-and-controlexploitationpenetration-testing+2
27 months ago
CVE-2024-10914-Exploit preview

CVE-2024-10914-Exploit

GitHubtamirido30/cve-2024-10914-exploit

CVE-2024-10914 Shell Exploit

command-and-controlexploitationpayload-generation+5
1 year ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
CVE-2025-3969-Exploit preview

CVE-2025-3969-Exploit

GitHubstuub/cve-2025-3969-exploit

CVE-2025-3969: Exploit PoC (OS CMD injection, Web Shell, Interactive Shell)

command-and-controlexploitationpayload-generation+3
21 year ago
nim-shell preview

nim-shell

GitHubemrekybs/nim-shell

Reverse shell that can bypass windows defender detection

command-and-controlexploitationids-ips-evasion+5
1795 months ago
CVE-2026-56290 preview

CVE-2026-56290

GitHubjenderal92/cve-2026-56290

CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP…

command-and-controleducationexploitation+5
52 months ago
Previous12…16Next