Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
233 results
CVE-2020-0796 preview

CVE-2020-0796

GitHuborangmuda/cve-2020-0796

Remote Code Execution POC for CVE-2020-0796

educationexploitationpayload-development+3
54 years ago
n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate preview

n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate

GitHubhackersatyamrastogi/n8n-exploit-cve-2025-68613-n8n-god-mode-ultimate

n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution

command-and-controleducationexploitation+8
59 months ago
log4j-cve-2021-44228 preview

log4j-cve-2021-44228

GitHubmanuel-alvarez-alvarez/log4j-cve-2021-44228

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

educationexploitationpayload-development+3
54 years ago
React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web preview

React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web

GitHubadityabhatt3010/react2shell-cve-2025-55182-the-deserialization-bug-that-broke-the-web

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

ctfeducationexploitation+8
89 months ago
CVE-2024-37054 preview

CVE-2024-37054

GitHubben-slates/cve-2024-37054

Proof-of-concept exploit for CVE-2024-37054, a pickle deserialization RCE in MLflow Tracking Server. Authenticated attackers can overwrite model…

educationexploitationpayload-development+3
54 months ago
CVE-2023-32571-POC preview

CVE-2023-32571-POC

GitHubtris0n/cve-2023-32571-poc

Proof-of-concept for CVE-2023-32571, demonstrating remote code execution via Dynamic Linq injection in ASP.NET applications. Includes payloads and a…

code-analysiseducationexploitation+4
72 years ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHubpastea/cve-2017-1000486

Multi-step proof-of-concept exploit for CVE-2017-1000486 (PrimeFaces EL injection) with padding oracle secret retrieval and blacklist-bypassing…

educationexploitationpayload-development+3
44 years ago
CVE-2024-6387-Exploit-POC preview

CVE-2024-6387-Exploit-POC

GitHubmrr0b0t19/cve-2024-6387-exploit-poc

Proof-of-concept exploit for CVE-2024-6387 targeting vulnerable OpenSSH servers via heap manipulation and race condition to achieve remote code…

binary-exploitationeducationexploitation+3
42 years ago
CVE-2019-11043 preview

CVE-2019-11043

GitHublindemer/cve-2019-11043

Python exploit for CVE-2019-11043 targeting PHP-FPM buffer underflow to achieve remote code execution via null byte overwrite and FastCGI variable…

educationexploitationpayload-development+3
45 years ago
CVE-2026-23918-Double-free-Apache-httpd-mod_http2 preview

CVE-2026-23918-Double-free-Apache-httpd-mod_http2

GitHubgagaltotal/cve-2026-23918-double-free-apache-httpd-mod_http2

Go-based proof-of-concept exploit for CVE-2026-23918 targeting a double-free vulnerability in Apache httpd mod_http2, enabling pre-auth remote code…

educationexploitationpayload-development+3
3 months ago
cve-2021-44228-rce-poc preview

cve-2021-44228-rce-poc

GitHububitech/cve-2021-44228-rce-poc

A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)

educationexploitationpayload-development+3
34 years ago
CVE-2025-55182-NextJS-RCE-PoC preview

CVE-2025-55182-NextJS-RCE-PoC

GitHubpkrasulia/cve-2025-55182-nextjs-rce-poc

Working Proof of Concept (PoC) for CVE-2025-55182 (React2Shell) - Unauthenticated Remote Code Execution in Next.js 15.0.0 via React Server Components

educationexploitationlabs-practice+3
49 months ago
parquet-rce-poc-CVE-2025-30065 preview

parquet-rce-poc-CVE-2025-30065

GitHubmouadk/parquet-rce-poc-cve-2025-30065

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

educationexploitationpayload-development+3
31 year ago
CVE-2021-21983 preview

CVE-2021-21983

GitHubmurataydemir/cve-2021-21983

[CVE-2021-21983] VMware vRealize Operations (vROps) Manager API Arbitrary File Write Leads to Remote Code Execution (RCE)

educationexploitationpayload-development+2
34 years ago
CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept preview

CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

GitHubkra1t0/cve-2025-33053-webdav-rce-poc-and-c2-concept

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

command-and-controleducationexploitation+5
31 year ago
CVE-2026-40176-poc preview

CVE-2026-40176-poc

GitHubsaku0512/cve-2026-40176-poc

Proof-of-concept for CVE-2026-40176, an OS command injection in Composer's Perforce driver allowing remote code execution via crafted composer.json.

command-and-controleducationexploitation+3
23 months ago
CVE-2026-38526-POC preview

CVE-2026-38526-POC

GitHubpawpic/cve-2026-38526-poc

Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution

educationexploitationpayload-development+3
13 months ago
CVE-2021-28378 preview

CVE-2021-28378

GitHubpandatix/cve-2021-28378

Detailed proof-of-concept and analysis of CVE-2021-28378, a stored XSS vulnerability in Gitea enabling arbitrary code injection, privilege…

educationexploitationpayload-development+3
48 months ago
Previous1…345…13Next