Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
376 results
CVE-2022-26809-RCE preview

CVE-2022-26809-RCE

GitHublay0us/cve-2022-26809-rce

This repository contains a PoC for remote code execution CVE-2022-26809

exploitationpayload-developmentpenetration-testing+2
4 years ago
vsftpd234-exploit preview

vsftpd234-exploit

GitHublghost256/vsftpd234-exploit

Exploit for CVE-2011-2523.

exploitationpayload-developmentpenetration-testing+2
1 year ago
PoC-for-CVE-2020-28948-CVE-2020-28949 preview

PoC-for-CVE-2020-28948-CVE-2020-28949

GitHubjinhao-l/poc-for-cve-2020-28948-cve-2020-28949

Proof-of-concept exploit for CVE-2020-28948 and CVE-2020-28949 targeting PHAR deserialization and inclusion vulnerabilities in Archive_Tar, enabling…

exploitationpayload-developmentpenetration-testing+3
3 years ago
CVE-2024-6387_Check preview

CVE-2024-6387_Check

GitHubhadesnull123/cve-2024-6387_check

RCE OpenSSH CVE-2024-6387 Check and Exploit

exploitationpayload-developmentpenetration-testing+2
2 years ago
weblogic-cve-2018-2628 preview

weblogic-cve-2018-2628

GitHubcscadoge/weblogic-cve-2018-2628

Exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution via ysoserial JRMP listener.

exploitationpayload-developmentpenetration-testing+3
4 years ago
CVE-2021-41773-L- preview

CVE-2021-41773-L-

GitHubmightysai1997/cve-2021-41773-l-

Proof-of-concept exploit for CVE-2021-41773, demonstrating path traversal and remote code execution on Apache HTTP Server 2.4.49 with a reverse shell…

exploitationpayload-developmentpenetration-testing+3
3 years ago
CVE-2021-42362 preview

CVE-2021-42362

GitHubsamiba6/cve-2021-42362

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the…

exploitationpayload-developmentremote-access-tool+2
1 year ago
cve-2007-2447 preview

cve-2007-2447

GitHubjuantos/cve-2007-2447

Samba 3.0.0 - 3.0.25rc3

exploitationpayload-developmentpenetration-testing+2
2 years ago
CVE-2020-8254 preview

CVE-2020-8254

GitHubmbadanoiu/cve-2020-8254

CVE-2020-8254: Zip Slip in Pulse Secure VPN Windows Client

exploitationpayload-developmentpenetration-testing+3
2 years ago
CVE-2011-2523-PoC preview

CVE-2011-2523-PoC

GitHub0xb0y426/cve-2011-2523-poc

PoC CVE-2011-2523

exploitationpayload-developmentpenetration-testing+2
2 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubdbgee/cve-2021-44228

Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.

exploitationpayload-developmentremote-access-tool+2
4 years ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubghostn4444/cve-2025-53770

CVE-2025-53770 - SharePoint

authentication-authorizationexploitationpayload-development+3
1 year ago
Project-Exploiting-CVE-2024-27198-RCE-Vulnerability preview

Project-Exploiting-CVE-2024-27198-RCE-Vulnerability

GitHubartemcyberlab/project-exploiting-cve-2024-27198-rce-vulnerability

In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2024-28397-js2py-Sandbox-Escape preview

CVE-2024-28397-js2py-Sandbox-Escape

GitHubcyber-warrior-sec/cve-2024-28397-js2py-sandbox-escape

Proof-of-concept exploit for CVE-2024-28397, a sandbox escape in js2py allowing remote code execution via crafted JavaScript, with a dynamic patch…

code-analysisexploitationpayload-development+3
2 years ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubthhardvester/cve-2025-24813

Remote Code Execution (RCE) vulnerability in Apache Tomcat.

exploitationpayload-developmentremote-access-tool+2
1 year ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud-native C2 framework using cloud storage as dead-drop communication channel

cloud-securitycommand-and-controlencryption-decryption-tools+6
42 days ago
CVE-2026-41940-Exploit-PoC preview

CVE-2026-41940-Exploit-PoC

GitHubishanoshada/cve-2026-41940-exploit-poc

Exploit PoC for CVE-2026-41940, a cPanel & WHM authentication bypass via CRLF injection. Includes mass scanning, post-exploitation actions, and an…

authentication-authorizationexploitationpayload-development+5
23 months ago
RunPE preview

RunPE

GitHubnettitude/runpe

C# Reflective loader for unmanaged binaries.

adversarial-attackimpersonation-toolspayload-development+6
4473 years ago
Previous1…192021Next