Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
82 results
CVE-2026-42945 preview

CVE-2026-42945

GitHubaratane/cve-2026-42945

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

binary-exploitationcommand-and-controleducation+6
1
3 months ago
CVE-2021-3064 preview

CVE-2021-3064

GitHub0xhaggis/cve-2021-3064

Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x

exploitationpayload-developmentpenetration-testing+3
13 years ago
CVE-2022-22965-Spring4Shell preview

CVE-2022-22965-Spring4Shell

GitHubkuri119/cve-2022-22965-spring4shell

Exploit for CVE-2022-22965 (Spring4Shell) enabling remote code execution on unpatched Spring Framework applications via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
3 months ago
Firefox-CVE-2016-9079 preview

Firefox-CVE-2016-9079

GitHubtau-hub/firefox-cve-2016-9079

Manual exploit for Firefox RCE CVE-2016-9079 with customizable shellcode, served via HTTP for remote code execution on vulnerable Windows systems.

exploitationpayload-developmentpenetration-testing+2
14 years ago
cve-2023-34040 preview

cve-2023-34040

GitHubhuyennhat-dev/cve-2023-34040

Proof-of-concept exploit for Spring Kafka deserialization RCE (CVE-2023-34040) with a crafted HTTP POST payload targeting vulnerable message brokers.

exploitationpayload-developmentremote-access-tool+2
12 years ago
CVE-2025-48799- preview

CVE-2025-48799-

GitHubgmh5225/cve-2025-48799-

Proof-of-concept exploit for CVE-2025-48799, an Apache Tomcat remote code execution vulnerability. Demonstrates integer overflow exploitation via…

binary-exploitationeducationexploitation+5
1 year ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubeserror/cve-2025-31161

Go-based exploit for CVE-2025-31161 targeting crushFTP, enabling remote admin account creation via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
7 months ago
Apache-CVE-2021-42013-RCE-Exploit preview

Apache-CVE-2021-42013-RCE-Exploit

GitHubfakhricrd/apache-cve-2021-42013-rce-exploit

A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code…

exploitationpayload-developmentpenetration-testing+3
11 months ago
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
16 months ago
CVE-2002-1120 preview

CVE-2002-1120

GitHubthemalwareguardian/cve-2002-1120

Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.

binary-exploitationdebuggerseducation+8
16 months ago
CVE-2023-22527 preview

CVE-2023-22527

GitHubkh4sh3i/cve-2023-22527

Proof-of-concept exploit for CVE-2023-22527, a Server-Side Template Injection (SSTI) vulnerability in Atlassian Confluence enabling remote code…

exploitationpayload-developmentpenetration-testing+2
11 year ago
CVE-2020-13768 preview

CVE-2020-13768

GitHubthemalwareguardian/cve-2020-13768

Stack-based buffer overflow in MiniShare 1.4.1 reachable through a single HTTP PUT request.

binary-exploitationdebuggerseducation+7
6 months ago
CVE-2025-24813-Apache-Tomcat-RCE-PoC preview

CVE-2025-24813-Apache-Tomcat-RCE-PoC

GitHubsentilaso1/cve-2025-24813-apache-tomcat-rce-poc

Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted…

educationexploitationpayload-development+3
11 year ago
CVE-2014-6271 preview

CVE-2014-6271

GitHubaruthw/cve-2014-6271

Exploit for CVE-2014-6271 (Shellshock) targeting vulnerable Bash environments, enabling remote code execution via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
8 years ago
CVE-2021-3007-docker-poc preview

CVE-2021-3007-docker-poc

GitHubyunus-a1i/cve-2021-3007-docker-poc

Reproducible Proof-of-Concept for CVE-2021-3007 (Laminas/Zend HTTP deserialization RCE) with a standalone exploit script, Nuclei template, and…

educationexploitationpayload-development+3
10 months ago
CVE-2017-5941-NodeJS-RCE preview

CVE-2017-5941-NodeJS-RCE

GitHubfrivolous-scholar/cve-2017-5941-nodejs-rce

Proof-of-concept exploit for CVE-2017-5941, a remote code execution vulnerability in Node.js. Demonstrates exploitation via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
6 years ago
CVE-2014-0226-poc preview

CVE-2014-0226-poc

GitHubshreesh1/cve-2014-0226-poc

Proof-of-concept exploit for CVE-2014-0226, targeting a man-in-the-middle vulnerability in Apache HTTP Server's mod_ssl to demonstrate SSL/TLS…

exploitationpayload-developmentpenetration-testing+2
5 years ago
axios-CVE-2025-27152-PoC preview

axios-CVE-2025-27152-PoC

GitHubdavidblakecoe/axios-cve-2025-27152-poc

Proof-of-concept exploit for CVE-2025-27152 in Axios, demonstrating a server-side request forgery vulnerability in the popular HTTP client library.

exploitationpayload-developmentpenetration-testing+2
1 year ago
Previous12345Next