Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
RSPET preview

RSPET

GitHubpanagiks/rspet

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

command-and-controlexploitationpayload-generation+4
263
8 years ago
CVE-2022-41343 preview

CVE-2022-41343

GitHubbkreisel/cve-2022-41343

🐍 Python Exploit for CVE-2022-23935

exploitationpayload-generationpenetration-testing+3
33 years ago
CVE-2022-42889-text4shell preview

CVE-2022-42889-text4shell

GitHubgoultarde/cve-2022-42889-text4shell

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code…

exploitationpayload-generationpenetration-testing+3
12 months ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubflojboj/cve-2021-31630

POC Exploit for CVE-2021-31630 written in Python3 and using C reverse shell with non-blocking mode

ctfeducationexploitation+3
2 years ago
CVE-2023-41425-RCE-WonderCMS-4.3.2 preview

CVE-2023-41425-RCE-WonderCMS-4.3.2

GitHubtea-on/cve-2023-41425-rce-wondercms-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

educationexploitationpayload-generation+5
81 year ago
IPFire_2.25_RCE_Authenticated preview

IPFire_2.25_RCE_Authenticated

GitHubjoaoaugustom/ipfire_2.25_rce_authenticated

This exploit is based on CVE-2021-33393 and was built upon the original exploit by Mücahit Saratar, extending it to achieve a reverse shell with root…

exploitationpenetration-testingprivilege-escalation+3
14 months ago
CVE-2023-45878 preview

CVE-2023-45878

GitHubdgoorden/cve-2023-45878

Python exploit for CVE-2023-45878 targeting Gibbon LMS 25.0.1. Uses arbitrary file write to upload a PHP web shell and execute a PowerShell reverse…

exploitationpayload-generationpenetration-testing+3
1 year ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
CVE-2025-2620-poc preview

CVE-2025-2620-poc

GitHubotsmane-ahmed/cve-2025-2620-poc

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

binary-exploitationembedded-systems-securityexploitation+8
161 year ago
CVE-2024-41570 preview

CVE-2024-41570

GitHubdiemoeve/cve-2024-41570

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

command-and-controlexploitationpayload-generation+5
111 year ago
nginxrift-CVE-2026-42945 preview

nginxrift-CVE-2026-42945

GitHubnanwinata/nginxrift-cve-2026-42945

Proof-of-concept exploit for CVE-2026-42945 (NGINX Rift) with multi-mode RCE, blind verification, reverse shell, and batch scanning capabilities for…

educationexploitationpayload-development+3
34 months ago
hfs-cve-2014-6287-exploit preview

hfs-cve-2014-6287-exploit

GitHubfrancescobrina/hfs-cve-2014-6287-exploit

Python-based exploit for CVE-2014-6287 in HTTP File Server 2.3.x, delivering a reverse shell via Base64-encoded PowerShell payload for authorized…

command-and-controleducationexploitation+5
1 year ago
POC-CVE-2020-0796 preview

POC-CVE-2020-0796

GitHubhungdnvp/poc-cve-2020-0796

Proof-of-concept exploit for CVE-2020-0796 (SMBGhost) targeting Windows 10/Server SMBv3.1.1. Includes Nmap reconnaissance, vulnerability scanning,…

exploitationnetwork-securitypenetration-testing+3
2 years ago
CVE-2020-24186_reverse_shell_upload preview

CVE-2020-24186_reverse_shell_upload

GitHubsubsting/cve-2020-24186_reverse_shell_upload

Exploit for CVE-2020-24186 in WordPress wpDiscuz 7.0.4 that uploads a reverse PHP shell for remote code execution.

exploitationpayload-generationpenetration-testing+3
142 years ago
CVE-2025-65018_Exploit_Challenge preview

CVE-2025-65018_Exploit_Challenge

GitHubbohemian-miser/cve-2025-65018_exploit_challenge

CTF challenge exploiting a heap overflow in libpng's png_image_finish_read to overwrite a function pointer and spawn a shell, with build scripts and…

binary-exploitationctfeducation+3
19 months ago
jankybank preview

jankybank

GitHubeurogig/jankybank

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

ctfeducationexploitation+3
2 years ago
Linksys-WRT54GL-Exploitation preview

Linksys-WRT54GL-Exploitation

GitHubumbertodellamonica/linksys-wrt54gl-exploitation

From Solder to Shell: Full Hardware Exploitation of the Linksys WRT54GL Router (CVE-2022-43973)

binary-analysisdebuggerseducation+9
24 months ago
CVE-2019-2215 preview

CVE-2019-2215

GitHubmufidmb38/cve-2019-2215

CVE-2019-2215

android-securitybinary-exploitationexploitation+3
35 years ago