Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
376 results
VortexCry-Ransomware-Release preview

VortexCry-Ransomware-Release

GitHubvortexcry-organization/vortexcry-ransomware-release

Advanced ransomware using process injection and kernel driver loading via CVE-2019-16098 to encrypt files, disable recovery, and demand ransom. For…

binary-exploitationencryption-decryption-toolsexploitation+3
1
6 months ago
CVE-2025-55182-React2Shell-CVSS-10.0- preview

CVE-2025-55182-React2Shell-CVSS-10.0-

GitHubgeorge0papasotiriou/cve-2025-55182-react2shell-cvss-10.0-

Python proof-of-concept exploit for CVE-2025-55182, a pre-authentication remote code execution vulnerability in React Server Components via insecure…

exploitationpayload-developmentpenetration-testing+3
16 months ago
HPE-iMC-7.3-RMI-Java-Deserialization preview

HPE-iMC-7.3-RMI-Java-Deserialization

GitHubscanfsec/hpe-imc-7.3-rmi-java-deserialization

CVE-2017-5792

exploitationpayload-developmentpenetration-testing+3
18 years ago
cve-2023-34040 preview

cve-2023-34040

GitHubhuyennhat-dev/cve-2023-34040

Proof-of-concept exploit for Spring Kafka deserialization RCE (CVE-2023-34040) with a crafted HTTP POST payload targeting vulnerable message brokers.

exploitationpayload-developmentremote-access-tool+2
12 years ago
CVE-2020-8840 preview

CVE-2020-8840

GitHubblyth0he/cve-2020-8840

jackson jndi injection

exploitationpayload-developmentremote-access-tool+2
16 years ago
CVE-2025-24813-PoC-exploit preview

CVE-2025-24813-PoC-exploit

GitHubgunyakit/cve-2025-24813-poc-exploit

Proof-of-concept exploit for Apache Tomcat deserialization RCE (CVE-2025-24813). Uploads a crafted session file via PUT request and triggers…

exploitationpayload-developmentpenetration-testing+3
8 months ago
CVE-2025-65753 preview

CVE-2025-65753

GitHubdiegovargasj/cve-2025-65753

Proof-of-concept exploit for CVE-2025-65753: remote code execution on Gryphon Guardian access point via improper TLS certificate validation, enabling…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2024-39840-POC preview

CVE-2024-39840-POC

GitHubwritegsqword/cve-2024-39840-poc

Proof-of-concept exploit for CVE-2024-39840, a remote code execution vulnerability in Factorio 1.1.86. Adapted from a detailed writeup, demonstrating…

binary-exploitationexploitationpayload-development+2
10 months ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubshadowroot97/react2shell-cve-2025-55182

POC React2Shell-CVE-2025-55182

exploitationpayload-developmentpenetration-testing+3
8 months ago
POC-CVE-2025-55182 preview

POC-CVE-2025-55182

GitHubnomorebreach/poc-cve-2025-55182

POC for CVE-2025-55182 React2Shell

exploitationpayload-developmentpenetration-testing+3
8 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubgrejh0t/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical unauthenticated RCE in React Server Components via unsafe deserialization in…

command-and-controlexploitationpayload-development+3
8 months ago
exploit-CVE-2017-7494 preview

exploit-CVE-2017-7494

GitHub00mjk/exploit-cve-2017-7494

SambaCry exploit (CVE-2017-7494)

exploitationpayload-developmentpenetration-testing+2
14 years ago
CVE-2022-1329 preview

CVE-2022-1329

GitHubdexit/cve-2022-1329

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

code-analysisexploitationpayload-development+3
3 years ago
CVE-2020-5903 preview

CVE-2020-5903

GitHubltvthang/cve-2020-5903

Exploit for CVE-2020-5902 targeting F5 BIG-IP RCE via path traversal and JDBC deserialization, enabling command execution, file read/write, and…

exploitationpayload-developmentpenetration-testing+3
6 years ago
Blackash-CVE-2025-0282 preview

Blackash-CVE-2025-0282

GitHubgmh5225/blackash-cve-2025-0282

Remote code execution exploit for CVE-2025-0282 targeting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. Uploads a web shell to…

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2025-24893-Reverse-Shell preview

CVE-2025-24893-Reverse-Shell

GitHubazureadtrent/cve-2025-24893-reverse-shell

Reverse Shell Payload for CVE-2025-24893

exploitationpayload-developmentpenetration-testing+3
1 year ago
WingFTP-CVE-2025-47812-illdeed preview

WingFTP-CVE-2025-47812-illdeed

GitHubill-deed/wingftp-cve-2025-47812-illdeed

Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2025-47812 preview

CVE-2025-47812

GitHubpopyue/cve-2025-47812

RCE for WingFTP v4.7.3

authenticationexploitationpayload-development+3
6 months ago
Previous1…18192021Next