Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
151 results
CVE-2024-21182---Oracle-WebLogic-Server-JNDI-Injection-RCE preview

CVE-2024-21182---Oracle-WebLogic-Server-JNDI-Injection-RCE

GitHubfevar54/cve-2024-21182---oracle-weblogic-server-jndi-injection-rce

Proof-of-concept exploit for CVE-2024-21182, an unauthenticated JNDI injection leading to remote code execution in Oracle WebLogic Server via T3/IIOP…

educationexploitationlabs-practice+4
3 months ago
CVE-2025-8625 preview

CVE-2025-8625

GitHubret0x2a/cve-2025-8625

Proof-of-concept exploit for CVE-2025-8625 targeting WordPress, with Docker-based isolated lab environment and demonstration web shell for…

educationexploitationlabs-practice+3
111 months ago
cve-2025-5025 preview

cve-2025-5025

GitHubkiphuong/cve-2025-5025

Proof-of-concept exploit for CVE-2025-5025, demonstrating the vulnerability with a Docker-based environment for testing and validation.

exploitationpayload-developmentpenetration-testing+2
1 year ago
CVE-2026-30345 preview

CVE-2026-30345

GitHubsyphonetic/cve-2026-30345

Proof-of-concept exploit for CVE-2026-30345, an arbitrary file write in CTFd backup import, enabling persistent backdoor via .bashrc.

exploitationpayload-developmentpenetration-testing+2
56 months ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4394 years ago
fawkes preview

fawkes

GitHubgaloryber/fawkes

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

cloud-securitycommand-and-controlcontainer-escape+7
382 months ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
49 months ago
PUG-RCE-CVE-2021-21353-POC preview

PUG-RCE-CVE-2021-21353-POC

GitHubjinsu9758/pug-rce-cve-2021-21353-poc

Proof-of-concept exploit for CVE-2021-21353, a remote code execution vulnerability in Pug template engine versions <=3.0.0. Demonstrates payload…

exploitationpayload-developmentpenetration-testing+2
21 year ago
CVE-2026-5843 preview

CVE-2026-5843

GitHubdavidrxchester/cve-2026-5843

Docker Container Escape POC via mlx-metal importlib

ai-securitycontainer-escapecontainer-security+4
4 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcc3305/cve-2025-55182

Pre-authentication RCE exploit for React Server Components (CVE-2025-55182). Targets unsafe deserialization in react-server-dom packages across…

exploitationpayload-developmentpenetration-testing+2
3 months ago
CVE-2024-21534 preview

CVE-2024-21534

GitHubpabloopez/cve-2024-21534

Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability

code-analysisexploitationpayload-development+2
11 year ago
CVE-2017-1000353 preview

CVE-2017-1000353

GitHubvulhub/cve-2017-1000353

jenkins CVE-2017-1000353 POC

exploitationpayload-developmentpenetration-testing+2
571 year ago
CVE-2025-63408 preview

CVE-2025-63408

GitHubs-vx/cve-2025-63408

Path Traversal in AgentDVR

exploitationpayload-developmentpenetration-testing+2
2 months ago
text4shell-exploit preview

text4shell-exploit

GitHubgokul-ramesh/text4shell-exploit

CVE-2022-42889 - Text4Shell exploit

exploitationpayload-developmentpenetration-testing+2
13 years ago
CVE-2023-50164-PoC preview

CVE-2023-50164-PoC

GitHubsunnyvale-it/cve-2023-50164-poc

CVE-2023-50164 (Apache Struts path traversal to RCE vulnerability) - Proof of Concept

exploitationpayload-developmentpenetration-testing+2
22 years ago
mariadb-13-rce-lab preview

mariadb-13-rce-lab

GitHubdinosn/mariadb-13-rce-lab

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

binary-exploitationdatabase-securityexploitation+5
641 month ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubpssec-io/cve-2026-48907

POC for CVE-2026-48907

educationexploitationlabs-practice+5
13 months ago
CVE-2023-32571-POC preview

CVE-2023-32571-POC

GitHubvert16x/cve-2023-32571-poc

Proof-of-concept exploit for CVE-2023-32571 demonstrating Dynamic Linq injection to achieve remote code execution, with a Docker-based lab…

code-analysiseducationexploitation+4
2 years ago
Previous1234…9Next