Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
CVE-2013-1081 preview

CVE-2013-1081

GitHubsteponequit/cve-2013-1081

Novell ZENworks Mobile Management - LFI RCE

exploitationexploit-frameworkspayload-development+3
2
13 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubprelearn-code/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

command-and-controlexploitationpayload-development+4
22 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubvuducmanhno100-cloud/cve-2024-6387

CVE-2024-6387 POC (Currently being edited)

exploitationpayload-developmentpenetration-testing+3
3 months ago
https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubfathanahhidayati/https-github.com-xaitax-cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

email-securityexploitationpassword-cracking+4
4 months ago
react2shell-poc-CVE-2025-55182 preview

react2shell-poc-CVE-2025-55182

GitHubtamagorengs/react2shell-poc-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182, a critical RCE vulnerability in Next.js Server Actions. Exploits insecure deserialization in the React…

code-analysiseducationexploitation+3
8 months ago
CVE-2025-4517-POC-Sudoers preview

CVE-2025-4517-POC-Sudoers

GitHubbgutowski/cve-2025-4517-poc-sudoers

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

exploitationpayload-developmentpenetration-testing+3
6 months ago
CVE-2024-415770-ssrf-rce preview

CVE-2024-415770-ssrf-rce

GitHub0dinox/cve-2024-415770-ssrf-rce

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

exploitationpayload-developmentpenetration-testing+3
11 year ago
XWiki-Platform-RCE-CVE-2025-24893 preview

XWiki-Platform-RCE-CVE-2025-24893

GitHub0xdtc/xwiki-platform-rce-cve-2025-24893

Bash exploit for CVE-2025-24893, unauthenticated RCE in XWiki Platform, using template injection in the SolrSearch macro to execute arbitrary system…

command-and-controlexploitationpayload-development+3
8 months ago
pickle_exploit preview

pickle_exploit

GitHubh3x0v3rl0rd/pickle_exploit

Demonstrating Remote Code Execution Vulnerability via Pickle Serialization in ClearML

code-analysiseducationexploitation+2
1 year ago
CVE-2025-30911 preview

CVE-2025-30911

GitHubnxploited/cve-2025-30911

WordPress RomethemeKit For Elementor Plugin <= 1.5.4 is vulnerable to Remote Code Execution (RCE)

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2024-21388 preview

CVE-2024-21388

GitHubd0rb/cve-2024-21388

This Python script exploits a vulnerability (CVE-2024-21388) in Microsoft Edge, allowing silent installation of browser extensions with elevated…

educationexploitationpayload-development+1
62 years ago
RCE-CVE-2025-3248 preview

RCE-CVE-2025-3248

GitHubtiemio/rce-cve-2025-3248

This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required…

exploitationpayload-developmentpenetration-testing+3
11 year ago
malvinci preview

malvinci

GitHubxgrxmey/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controlpayload-developmentremote-access-trojan
591 year ago
cve-2021-31630 preview

cve-2021-31630

GitHubthewhiteh4t/cve-2021-31630

Python script for exploiting command injection in Open PLC Webserver v3

command-and-controlexploitationpayload-development+3
212 years ago
ShatteredFTP preview

ShatteredFTP

GitHubghostsec420/shatteredftp

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

exploitationpayload-developmentpenetration-testing+3
131 year ago
CVE-2023-25581 preview

CVE-2023-25581

GitHubp33d/cve-2023-25581

Python exploit script for CVE-2023-25581, achieving remote code execution via deserialization of Base64-encoded data in pac4j-core.

exploitationpayload-developmentpenetration-testing+2
1 year ago
cve-2026-27483 preview

cve-2026-27483

GitHubthewhiteh4t/cve-2026-27483

MindsDB Path Traversal to RCE PoC

exploitationpayload-developmentpenetration-testing+3
55 months ago
CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050- preview

CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050-

GitHubsic4rio/cve-2009-3103---srv2.sys-smb-code-execution-python-ms09-050-

Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)

binary-exploitationeducationexploitation+3
42 years ago
Previous12345Next