Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
CVE-2026-29053 preview

CVE-2026-29053

GitHubk3ystr0k3r/cve-2026-29053

Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

exploitationpayload-developmentpenetration-testing+5
1
1 day ago
CVE-2026-33017-langflow-rce preview

CVE-2026-33017-langflow-rce

GitHubarensballiu/cve-2026-33017-langflow-rce

Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious…

exploitationpayload-developmentpenetration-testing+3
8 days ago
Flowise-RCE-CVE-2025-59528 preview

Flowise-RCE-CVE-2025-59528

GitHubarensballiu/flowise-rce-cve-2025-59528

Python PoC exploit for CVE-2025-59528, achieving authenticated RCE on Flowise AI <= 3.0.4 via the customMCP endpoint and Node.js…

exploitationpayload-developmentpenetration-testing+3
18 days ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubahmedmamdouh6/cve-2017-14980

CVE-2017-14980 python exploitation to RCE

binary-exploitationexploitationpayload-development+2
4 months ago
cve-2025-8110-GOGS-RCE preview

cve-2025-8110-GOGS-RCE

GitHubkayl22/cve-2025-8110-gogs-rce

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

command-and-controlexploitationpayload-development+4
45 months ago
CVE-2022-41840-PoC preview

CVE-2022-41840-PoC

GitHubprinceaikinsbaidoo/cve-2022-41840-poc

This is the PoC exploit for CVE-2022-41840, running Zenario

educationexploitationpayload-development+3
7 months ago
CVE-2025-4517-POC-Sudoers preview

CVE-2025-4517-POC-Sudoers

GitHubbgutowski/cve-2025-4517-poc-sudoers

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2024-48990-Automatic-Exploit preview

CVE-2024-48990-Automatic-Exploit

GitHubserner77/cve-2024-48990-automatic-exploit

Automated local privilege escalation exploit for CVE-2024-48990 (needrestart v3.7), leveraging PYTHONPATH hijacking to gain root access.

educationexploitationpayload-development+3
911 months ago
CVE-2019-7069-POC preview

CVE-2019-7069-POC

GitHubcaelumisme/cve-2019-7069-poc

Python 3 exploit for Kibana < 6.6.1 RCE (CVE-2019-7609) via prototype pollution, with automatic version detection and optional reverse shell.

educationexploitationpayload-development+3
11 months ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubbolivarj/cve-2011-2523

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

exploitationexploit-frameworkspayload-development+3
41 year ago
CVE-2019-13272 preview

CVE-2019-13272

GitHubjosemlwdf/cve-2019-13272

This is a Python 3 version of this exploit. Hope it works!!!

binary-exploitationexploitationpayload-development+3
31 year ago
CVE-2025-24016-Wazuh-Remote-Code-Execution-RCE-PoC preview

CVE-2025-24016-Wazuh-Remote-Code-Execution-RCE-PoC

GitHubcybersecplayground/cve-2025-24016-wazuh-remote-code-execution-rce-poc

A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects…

command-and-controlexploitationpayload-development+4
21 year ago
CVE-2024-54160-Opensearch-HTML-And-Injection-Stored-XSS preview

CVE-2024-54160-Opensearch-HTML-And-Injection-Stored-XSS

GitHubjflye/cve-2024-54160-opensearch-html-and-injection-stored-xss

Proof-of-concept exploit for CVE-2024-54160 demonstrating stored XSS and HTML injection in OpenSearch Reports plugin via malicious iframe payload in…

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2024-25641 preview

CVE-2024-25641

GitHubd3ext/cve-2024-25641

Proof-of-concept exploit for CVE-2024-25641, an authenticated RCE in Cacti 1.2.26 via the Package Import feature, enabling arbitrary PHP code…

exploitationpayload-developmentpenetration-testing+2
11 year ago
CVE-2021-44228 preview

CVE-2021-44228

GitHublucaspdiniz/cve-2021-44228

Log4j Vulnerability RCE - CVE-2021-44228

educationexploitationpayload-development+4
2 years ago
CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050- preview

CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050-

GitHubsic4rio/cve-2009-3103---srv2.sys-smb-code-execution-python-ms09-050-

Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)

binary-exploitationeducationexploitation+3
42 years ago
FuguHub-8.4-Authenticated-RCE-CVE-2024-27697 preview

FuguHub-8.4-Authenticated-RCE-CVE-2024-27697

GitHubsanjindedic/fuguhub-8.4-authenticated-rce-cve-2024-27697

Arbitrary Code Execution on FuguHub 8.4

command-and-controlexploitationpayload-development+5
102 years ago
CVE-2019-16784-POC preview

CVE-2019-16784-POC

GitHubckrielle/cve-2019-16784-poc

A Proof of Concept exploit for the PyInstaller CVE-2019-16783

binary-exploitationeducationexploitation+4
2 years ago
Previous12Next