Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
256 results
cve-2025-63888-exploit preview

cve-2025-63888-exploit

GitHuban5i/cve-2025-63888-exploit

Security research tool for detecting and testing CVE-2025-63888 (ThinkPHP 5.0.24 File Inclusion RCE vulnerability)

command-and-controlexploitationpayload-development+4
10
9 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubjenderal92/cve-2026-41940

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

authenticationcommand-and-controlexploitation+6
43 months ago
RevShell preview

RevShell

GitHubdragon56yt/revshell

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

command-and-controldata-exfiltrationeducation+8
23 months ago
Langflow-cve-2026-33017-exploit preview

Langflow-cve-2026-33017-exploit

GitHubcerberusmrxi/langflow-cve-2026-33017-exploit

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

command-and-controldata-exfiltrationexploitation+8
21 month ago
CVE-2026-5027-Langflow preview

CVE-2026-5027-Langflow

GitHublayer-6/cve-2026-5027-langflow

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

command-and-controlexploitationpayload-development+8
2 months ago
CVE-2025-55182-Exploit-PoC-Scanner preview

CVE-2025-55182-Exploit-PoC-Scanner

GitHubzemarkhos/cve-2025-55182-exploit-poc-scanner

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and…

command-and-controldynamic-analysis-sandboxingeducation+7
29 months ago
cve-2025-64446-fortiweb-exploit preview

cve-2025-64446-fortiweb-exploit

GitHuban5i/cve-2025-64446-fortiweb-exploit

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

educationexploitationpayload-development+5
19 months ago
Apache-CVE-2021-42013-RCE-Exploit preview

Apache-CVE-2021-42013-RCE-Exploit

GitHubfakhricrd/apache-cve-2021-42013-rce-exploit

A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code…

exploitationpayload-developmentpenetration-testing+3
10 months ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubluoqichen/cve-2025-55182-poc

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

command-and-controlexploitationpayload-development+5
6 months ago
Rust_CVE-2025-55182 preview

Rust_CVE-2025-55182

GitHubzorejt/rust_cve-2025-55182

Rust-based exploit tool for CVE-2025-55182, enabling remote code execution on react-server-dom-webpack servers via crafted multipart requests with…

exploitationpayload-developmentpenetration-testing+3
9 months ago
CVE-2024-31317-Deployer preview

CVE-2024-31317-Deployer

GitHubkalibb/cve-2024-31317-deployer

Automated deployment tool for CVE-2024-31317, a command injection vulnerability in Android 9-13. Includes reverse shell payload, compile script, and…

android-securitybinary-exploitationcommand-and-control+5
7 months ago
teletunnel preview

teletunnel

GitHubmhdgning131/teletunnel

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

command-and-controldata-exfiltrationids-ips-evasion+7
445 months ago
CVE-2025-9491_POC preview

CVE-2025-9491_POC

GitHubamperclock/cve-2025-9491_poc

Proof-of-Concept of the CVE-2025-9491 using invisible characters in the arguments of a Windows shortcut file (.lnk)

binary-analysiseducationexploitation+3
189 months ago
WP2Shell preview

WP2Shell

GitHubg0d150ne/wp2shell

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

exploitationexploit-frameworkspayload-development+7
23 days ago
CVE-2026-6279.py preview

CVE-2026-6279.py

GitHub87achrafg-stack/cve-2026-6279.py

CVE-2026-6279

command-and-controlexploitationpayload-development+5
12 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHublutfifakee-project/cve-2026-41940

cPanel/WHM CVE-2026-41940 - Mass Scanner & Exploiter

authenticationcommand-and-controlexploitation+6
24 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcarlosaruy/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

ctfeducationexploitation+6
9 months ago
Freeze.rs preview
Archived

Freeze.rs

GitHuboptiv/freeze.rs

Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST

anti-botencryption-decryption-toolsexploitation+3
7153 years ago
Previous123…15Next