Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
80 results
CVE-2025-39601 preview

CVE-2025-39601

GitHubnxploited/cve-2025-39601

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

ctfeducationexploitation+3
11 year ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubflojboj/cve-2023-42793

TeamCity CVE-2023-42793 RCE (Remote Code Execution)

ctfeducationexploitation+3
2 years ago
reverse-ssh preview

reverse-ssh

GitHubfahrj/reverse-ssh

Statically-linked ssh server with reverse shell functionality for CTFs and such

ctfpenetration-testingpost-exploitation+2
1.1k3 years ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubadityabhatt3010/react2shell-cve-2025-55182

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

code-analysisctfeducation+6
72 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubez4rd1x1/cve-2026-8181

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

authentication-authorizationctfeducation+5
3 months ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubgiangdurian/cve-2026-63030-cve-2026-60137

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

ctfeducationexploitation+4
2 months ago
CVE-2020-0022 preview

CVE-2020-0022

GitHubkalibb/cve-2020-0022

Zero-click Bluetooth RCE exploit for Android 8-9 (CVE-2020-0022) with heap spraying, address leaking, and JOP chain execution for remote code…

android-securitybinary-exploitationbluetooth-security+9
7 months ago
wp2shell-Wordpress-TOWN preview

wp2shell-Wordpress-TOWN

GitHublucifer0xf/wp2shell-wordpress-town

Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining…

code-analysisctfeducation+3
22 months ago
cve-2024-4577-lab preview

cve-2024-4577-lab

GitHubkhwajasaad267-coder/cve-2024-4577-lab

Docker-based CTF lab demonstrating CVE-2024-4577 PHP-CGI argument injection leading to RCE. Includes vulnerable PHP 5.4.1 CGI, exploit scripts, and…

ctfeducationexploitation+4
1 month ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
6 months ago
OptixGate preview

OptixGate

GitHubdarkcodersc/optixgate

Open-source multi-purpose remote access tool for Microsoft Windows

ctfeducationpost-exploitation+1
2076 months ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubrahul-securify/react2shell-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 demonstrating remote code execution in Next.js via prototype pollution. Includes a pre-configured…

ctfeducationexploitation+3
9 months ago
LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubc-g-creator/letsdefend-soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

ctfeducationemail-security+6
4 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcarlosaruy/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

ctfeducationexploitation+6
9 months ago
CVE-2026-42945-Reverse-Shell-POC preview

CVE-2026-42945-Reverse-Shell-POC

GitHubsec-sys/cve-2026-42945-reverse-shell-poc

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

binary-exploitationctfexploitation+6
3 months ago
CVE-2022-25765 preview

CVE-2022-25765

GitHubinnocentx0/cve-2022-25765

Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.

command-and-controlctfeducation+4
26 days ago
CVE-2026-30225-OliveTin-RCE preview

CVE-2026-30225-OliveTin-RCE

GitHubhackerking24/cve-2026-30225-olivetin-rce

Proof-of-concept exploit for OliveTin unauthenticated RCE (CVE-2026-30225) via insecure guest defaults and unvalidated argument types, enabling root…

ctfeducationexploitation+5
20 days ago
cve-2024-36401-geoserver-rce preview

cve-2024-36401-geoserver-rce

GitHubdanielegiovanardi2408/cve-2024-36401-geoserver-rce

Reproducible study of CVE-2024-36401: unauthenticated RCE in GeoServer via JXPath eval injection. Includes technical report, working…

ctfeducationexploitation+3
3 months ago
Previous12345Next