Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
71 results
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
409
14h 28m ago
htb-labs-connected preview

htb-labs-connected

GitHubdiegorivas1/htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

ctfeducationexploitation+7
7 days ago
cowrie preview

cowrie

GitHubcowrie/cowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

defensive-toolsincident-responseinformation-gathering+3
6.5k12 days ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
24 days ago
couchdb-exploit preview

couchdb-exploit

GitHubdarabium/couchdb-exploit

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

exploitationinformation-gatheringpenetration-testing+4
25 days ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubheltonpojo/cve-2025-32432

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

authentication-authorizationexploitationinformation-gathering+3
1 month ago
spectre-meltdown-checker preview

spectre-meltdown-checker

GitHubspeed47/spectre-meltdown-checker

Reptar, Downfall, Zenbleed, ZombieLoad, RIDL, Fallout, Foreshadow, Spectre, Meltdown vulnerability/mitigation checker for Linux & BSD

defensive-toolseducationhardware-iot-security+5
3.9k1 month ago
CVE-2026-42533 preview

CVE-2026-42533

GitHubimbas007/cve-2026-42533

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

binary-exploitationexploitationinformation-gathering+4
351 month ago
Discuz-X5.0-Authentication-Bypass-Exploit-Framework preview

Discuz-X5.0-Authentication-Bypass-Exploit-Framework

GitHubcerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

authentication-authorizationdatabase-securityexploit-frameworks+4
11 month ago
internal-penetration-testing-project-using-Metasploit preview

internal-penetration-testing-project-using-Metasploit

GitHubabdullah50i/internal-penetration-testing-project-using-metasploit

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

exploitationexploit-frameworksinformation-gathering+6
1 month ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
11 month ago
WP-Bricks-Exploit-CVE-2024-25600 preview

WP-Bricks-Exploit-CVE-2024-25600

GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

command-and-controlexploitationinformation-gathering+7
11 month ago
nimrm preview

nimrm

GitHubblue0x1/nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

authenticationcommand-and-controlinformation-gathering+6
61 month ago
CVE-2026-14762-PoC-Exploit preview

CVE-2026-14762-PoC-Exploit

GitHubtc4dy/cve-2026-14762-poc-exploit

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

command-and-controldatabase-securityexploitation+7
21 month ago
CVE-2026-42945-NGINX-Rift preview

CVE-2026-42945-NGINX-Rift

GitHubrenison-gohel/cve-2026-42945-nginx-rift

Python exploit for CVE-2026-42945 (NGINX Rift) with reverse shell capability and Shodan-based target discovery for penetration testing.

exploitationinformation-gatheringpenetration-testing+3
13 months ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
63 months ago
nextssrf preview

nextssrf

GitHubynsmroztas/nextssrf

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

cloud-securityexploitationinformation-gathering+3
773 months ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4 months ago
Previous1234Next