Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
80 results
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubgiangdurian/cve-2026-63030-cve-2026-60137

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

ctfeducationexploitation+4
2 months ago
cve-2024-4577-lab preview

cve-2024-4577-lab

GitHubkhwajasaad267-coder/cve-2024-4577-lab

Docker-based CTF lab demonstrating CVE-2024-4577 PHP-CGI argument injection leading to RCE. Includes vulnerable PHP 5.4.1 CGI, exploit scripts, and…

ctfeducationexploitation+4
1 month ago
CVE-2026-60004-gitea-0day preview

CVE-2026-60004-gitea-0day

GitHubsachinart/cve-2026-60004-gitea-0day

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

ctfexploitationpenetration-testing+3
1 month ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubcd-ratel/cve-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

ctfeducationexploitation+4
24 months ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubbayu06802/cve-2026-48908

Proof-of-concept exploit for CVE-2026-48908, an unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload, with adaptive payload…

ctfeducationexploitation+4
2 months ago
CVE-2023-28467 preview

CVE-2023-28467

GitHubahmetaltuntas/cve-2023-28467

Proof-of-concept for a persistent XSS vulnerability in MyBB 1.8.33 User CP, allowing authenticated users to inject HTML via the email field, with…

ctfeducationpenetration-testing+2
43 years ago
react2shellexploitvisualized preview

react2shellexploitvisualized

GitHubvolksrat71/react2shellexploitvisualized

Interactive visualization of the React2Shell (CVE-2025-55182) RCE vulnerability with narrated animations for three audiences: Expert, Practitioner,…

ctfeducationexploitation+3
39 months ago
Blackash-CVE-2025-55182 preview

Blackash-CVE-2025-55182

GitHubshen771/blackash-cve-2025-55182

CVE-2025-55182

command-and-controlctfeducation+7
9 months ago
react2shell preview

react2shell

GitHubdr4xp/react2shell

A critical vulnerability in React Server Components affecting React 19 (CVE-2025-55182) and frameworks that use it like Next.js (CVE-2025-66478).

ctfeducationexploitation+3
29 months ago
CVE-2026-42945-Reverse-Shell-POC preview

CVE-2026-42945-Reverse-Shell-POC

GitHubsec-sys/cve-2026-42945-reverse-shell-poc

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

binary-exploitationctfexploitation+6
3 months ago
cve-2024-36401-geoserver-rce preview

cve-2024-36401-geoserver-rce

GitHubdanielegiovanardi2408/cve-2024-36401-geoserver-rce

Reproducible study of CVE-2024-36401: unauthenticated RCE in GeoServer via JXPath eval injection. Includes technical report, working…

ctfeducationexploitation+3
3 months ago
Drupal_REST-RCE_Unauthenticated preview

Drupal_REST-RCE_Unauthenticated

GitHubjoaoaugustom/drupal_rest-rce_unauthenticated

This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed…

ctfeducationexploitation+3
4 months ago
htb-sau-exploit-chain preview

htb-sau-exploit-chain

GitHubtombstoneghost/htb-sau-exploit-chain

Automated exploit chain for HTB Sau — CVE-2023-27163 (SSRF) + Maltrail Unauthenticated RCE → Reverse Shell

ctfeducationexploitation+3
5 months ago
react-rsc-cve-2025-55182-lab preview

react-rsc-cve-2025-55182-lab

GitHubjeanback1/react-rsc-cve-2025-55182-lab

Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol

code-analysisctfeducation+4
4 months ago
LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubc-g-creator/letsdefend-soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

ctfeducationemail-security+6
4 months ago
CVE-2025-39601 preview

CVE-2025-39601

GitHubnxploited/cve-2025-39601

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

ctfeducationexploitation+3
11 year ago
CVE-2025-49132_HTB_SEASON10 preview

CVE-2025-49132_HTB_SEASON10

GitHubahmedf000/cve-2025-49132_htb_season10

Unauthenticated RCE exploit for CVE-2025-49132 in Pterodactyl Panel via path traversal, PEAR command injection, and PHP code execution. Includes HTB…

ctfeducationexploitation+3
7 months ago
Tryhackme_Billing preview

Tryhackme_Billing

GitHubcankunwang/tryhackme_billing

Billing CTF Machine_CVE-2023-30258_Remote Code Execution

ctfexploitationpenetration-testing+2
10 months ago
Previous12345Next