Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
449 results
Blackash-CVE-2025-33073 preview

Blackash-CVE-2025-33073

GitHubirjfifndn-prog/blackash-cve-2025-33073

CVE-2025-33073

command-and-controlexploitationlateral-movement+4
9 months ago
CVE-2025-11953-PoC preview

CVE-2025-11953-PoC

GitHubboroeurnprach/cve-2025-11953-poc

CVE-2025-11953 - The React Native Metro server's default external binding exposes a vulnerable endpoint, allowing unauthenticated attackers to…

exploitationpayload-developmentpenetration-testing+2
7 months ago
CVE-2025-22457 preview

CVE-2025-22457

GitHubtrone-ux/cve-2025-22457

PoC CVE-2025-22457

binary-exploitationexploitationexploit-frameworks+8
11 year ago
FiberBreak preview

FiberBreak

GitHubscumfrog/fiberbreak

React2Shell Exploitation Tool (CVE-2025-55182)

cloud-securitycommand-and-controldata-exfiltration+8
8 months ago
CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit preview

CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit

GitHubsimoesctt/ctt-serverless-rce-v1.0---convergent-time-theory-enhanced-mcp-exploit

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

ai-securitycloud-securitycommand-and-control+8
7 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xblackash/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182: unauthenticated RCE in React Server Components via unsafe deserialization, enabling arbitrary command…

exploitationpayload-developmentpenetration-testing+3
6 months ago
PoC-RCE-CVE-2025-55182 preview

PoC-RCE-CVE-2025-55182

GitHubilixm/poc-rce-cve-2025-55182

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

command-and-controlexploitationinformation-gathering+7
8 months ago
CVE_2025_68413-4 preview

CVE_2025_68413-4

GitHubmarshall-hallenbeck/cve_2025_68413-4

Disclosure and PoCs for CVE-2025-68413 and CVE-2025-68414

exploitationinformation-gatheringpayload-development+2
6 months ago
CVE-2025-65753 preview

CVE-2025-65753

GitHubdiegovargasj/cve-2025-65753

Proof-of-concept exploit for CVE-2025-65753: remote code execution on Gryphon Guardian access point via improper TLS certificate validation, enabling…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2024-57366 preview

CVE-2024-57366

GitHubh4ckusaur/cve-2024-57366

Remote code execution exploit for CVE-2024-57366 targeting WAVLINK routers via MAC address validation bypass and command injection, with automatic…

command-and-controlexploitationiot-security+6
11 months ago
CVE-2025-9435 preview

CVE-2025-9435

GitHubpasstheticket/cve-2025-9435

ADManager Plus Build < 7230 Elevation of Privilege

exploitationpayload-developmentpenetration-testing+2
8 months ago
CVE-2025-60787 preview

CVE-2025-60787

GitHubagent-skywalker/cve-2025-60787

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

command-and-controlexploitationpassword-attacks+5
5 months ago
WingFTP-CVE-2025-47812-illdeed preview

WingFTP-CVE-2025-47812-illdeed

GitHubill-deed/wingftp-cve-2025-47812-illdeed

Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2024-31771 preview

CVE-2024-31771

GitHubrestdone/cve-2024-31771

Proof-of-concept exploit for CVE-2024-31771 demonstrating arbitrary file write in TotalAV via symbolic link attack, enabling DLL planting and SYSTEM…

binary-exploitationexploitationlateral-movement+4
2 years ago
SIGINT_THROUGH_BROTHER_PRINTERS preview

SIGINT_THROUGH_BROTHER_PRINTERS

GitHubspiralbl0ck/sigint_through_brother_printers

Exploit vulnerable Brother printers via CVE-2017-7588, collect data, and develop custom firmware implants for attack simulation.

embedded-systems-securityexploitationfirmware-analysis+6
2 years ago
cobaltstrike4.5_cdf-1 preview

cobaltstrike4.5_cdf-1

GitHubzeoday/cobaltstrike4.5_cdf-1

cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等

authenticationbinary-analysiscommand-and-control+8
3 years ago
CVE-2025-25706 preview

CVE-2025-25706

GitHubcotherm/cve-2025-25706

Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality,…

command-and-controlexploitationpayload-development+3
1 year ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
Previous1…22232425Next