Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
27 results
CVE-2025-55182-poc preview

CVE-2025-55182-poc

GitHubuwugreed/cve-2025-55182-poc

I know you are probably here from Hack the Box, if so, yes this one actually works.

exploitationpayload-developmentpenetration-testing+3
1 month ago
CVE-2026-20079 preview

CVE-2026-20079

GitHubcyberauth/cve-2026-20079

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

authenticationexploitationpayload-development+3
61 month ago
CVE-2024-56426 preview

CVE-2024-56426

GitHubxcracker000/cve-2024-56426

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

android-securitybinary-exploitationembedded-systems-security+7
41 month ago
CVE-2026-33937 preview

CVE-2026-33937

GitHubc0gnit00/cve-2026-33937

Python POC, Exploit for Handlebars.js AST Injection RCE, Handlebars.js versions 4.0.0 through 4.7.8 are affected. CVSS score: 9.8 Critical.

educationexploitationpayload-development+3
11 month ago
CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE- preview

CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-

GitHubdhananjayasj/cve-2025-24813-apache-tomcat-partial-put-deserialization-rce-

Proof-of-concept exploit for CVE-2025-24813, an unauthenticated RCE in Apache Tomcat via partial PUT and deserialization. Includes Docker lab for…

exploitationlabs-practicepayload-development+3
3 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubchristian93111/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authenticationcommand-and-controleducation+6
94 months ago
Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE preview

Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE

GitHublu3ky13/alternative-approach-reverse-shell-callback-test-invokeai-rce

This repository contains alternative payload approaches for the InvokeAI RCE vulnerability (CVE-2024-12029) when SSH key injection fails. The…

command-and-controleducationexploitation+5
5 months ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubyoyochaud/cve-2025-49132

Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.

exploitationpayload-developmentpenetration-testing+3
257 months ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubwand3rlust/cve-2025-3248

PoC for achieving RCE in Langflow versions <1.3.0

command-and-controlexploitationpayload-development+3
8 months ago
UniPwn preview

UniPwn

GitHubbin4ry/unipwn

BLE exploit framework for Unitree robots: command injection via hardcoded AES keys enables remote takeover, payload injection, and wormable…

bluetooth-securityexploitationexploit-frameworks+4
41911 months ago
CVE-2019-18935-bypasswaf preview

CVE-2019-18935-bypasswaf

GitHubekkoo-z/cve-2019-18935-bypasswaf

Exploit for CVE-2019-18935 (Telerik UI) with WAF bypass via encrypted cookie payload injection and custom memory shell deployment.

exploitationpayload-developmentpenetration-testing+3
71 year ago
shellnoob preview

shellnoob

GitHubreyammer/shellnoob

A shellcode writing toolkit

binary-analysisdebuggerseducation+6
6961 year ago
CVE-2024-7808 preview

CVE-2024-7808

GitHubtheunknownsoul/cve-2024-7808

RCE exploit for low privileged user via CSRF in open-webui

exploitationpayload-developmentpenetration-testing+2
21 year ago
PolyDrop preview

PolyDrop

GitHubmalwaresupportgroup/polydrop

A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit

command-and-controldefensive-toolseducation+5
1252 years ago
Commander preview

Commander

GitHubvoukatas/commander

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

command-and-controlencryption-decryption-toolspayload-development+3
632 years ago
LazySign preview

LazySign

GitHubjfmaes/lazysign

Create fake certs for binaries using windows binaries and the power of bat files

binary-analysisdefensive-toolsimpersonation-tools+6
5692 years ago
DC30_Workshop preview

DC30_Workshop

GitHubmainframed/dc30_workshop

DEFCON 30 Mainframe buffer overlow workshop container

binary-exploitationeducationexploitation+4
962 years ago
MorphAES preview

MorphAES

GitHubcryptolok/morphaes

IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…

binary-exploitationexploitationids-ips-evasion+4
3254 years ago
Previous12Next