Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
199 results
Solar-exploiting-log-4j preview

Solar-exploiting-log-4j

GitHublathika-3006/solar-exploiting-log-4j

Step-by-step TryHackMe walkthrough for exploiting the Log4Shell vulnerability (CVE-2021-44228) to achieve remote code execution and capture flags.

educationexploitationlabs-practice+6
2
6 months ago
CVE-2025-24893 preview

CVE-2025-24893

GitHubibadovulfat/cve-2025-24893

A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.

educationexploitationlabs-practice+2
8 months ago
CVE-2023-22527-POC preview

CVE-2023-22527-POC

GitHubmaanvader/cve-2023-22527-poc

Atlassian Confluence Remote Code Execution(RCE) Proof Of Concept

educationexploitationlabs-practice+3
12 years ago
exploit-CVE-2016-10033 preview

exploit-CVE-2016-10033

GitHubopsxcq/exploit-cve-2016-10033

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

code-analysiseducationexploitation+6
4076 years ago
RemoteTLSCallbackInjection preview

RemoteTLSCallbackInjection

GitHubmaldev-academy/remotetlscallbackinjection

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

binary-exploitationeducationlabs-practice+1
2902 years ago
exploit-CVE-2015-3306 preview

exploit-CVE-2015-3306

GitHubt0kx/exploit-cve-2015-3306

ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container

educationexploitationlabs-practice+3
1518 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubdoocop/cve-2022-30190

Reproduction of CVE-2022-30190 (Follina) remote code execution vulnerability in Microsoft Office Word via malicious docx/rtf files with ms-msdt…

educationexploitationlabs-practice+3
594 years ago
CVE-2020-8163 preview

CVE-2020-8163

GitHublucasamorimca/cve-2020-8163

CVE-2020-8163 - Remote code execution of user-provided local names in Rails

educationexploitationlabs-practice+2
603 years ago
PIL-RCE-Ghostscript-CVE-2018-16509 preview

PIL-RCE-Ghostscript-CVE-2018-16509

GitHubfarisv/pil-rce-ghostscript-cve-2018-16509

PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509

educationexploitationlabs-practice+2
627 years ago
CVE-2020-8840 preview

CVE-2020-8840

GitHubfairyming/cve-2020-8840

PoC exploit for CVE-2020-8840: JNDI injection leading to remote code execution in FasterXML jackson-databind. Includes environment setup, exploit…

code-analysiseducationexploitation+3
376 years ago
exploit-CVE-2015-1427 preview

exploit-CVE-2015-1427

GitHubt0kx/exploit-cve-2015-1427

Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container

educationexploitationlabs-practice+3
328 years ago
CVE-2026-4480-PoC preview

CVE-2026-4480-PoC

GitHubthecybergeek/cve-2026-4480-poc

Proof-of-concept exploit for CVE-2026-4480, an unauthenticated remote command execution in Samba's print subsystem via %J injection. Includes reverse…

ctfeducationexploitation+3
223 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubthemehackers/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

educationexploitationlabs-practice+3
217 months ago
poc-cve-2025-55182 preview

poc-cve-2025-55182

GitHubkoadt/poc-cve-2025-55182

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

code-analysisctfdynamic-analysis-sandboxing+7
156 months ago
CVE-2025-1302 preview

CVE-2025-1302

GitHubeqstlab/cve-2025-1302

JSONPath-plus Remote Code Execution

educationexploitationlabs-practice+3
211 year ago
Spring-Cloud-Function-SpEL preview

Spring-Cloud-Function-SpEL

GitHubpizz33/spring-cloud-function-spel

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

educationexploitationlabs-practice+2
244 years ago
Ultimate-wp2shell preview

Ultimate-wp2shell

GitHubcodeb0ssx/ultimate-wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route…

educationexploitationlabs-practice+3
102 months ago
cve-2022-24112 preview

cve-2022-24112

GitHubtwseptian/cve-2022-24112

Apache APISIX < 2.12.1 Remote Code Execution and Docker Lab

educationexploitationlabs-practice+3
94 years ago
Previous12…12Next