Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
CVE-2025-66478-Exploit-Poc preview

CVE-2025-66478-Exploit-Poc

GitHubnamest504/cve-2025-66478-exploit-poc

Proof-of-concept exploit for Next.js CVE-2025-66478, demonstrating RCE via insecure deserialization and prototype pollution in Server Actions.…

educationexploitationpayload-development+3
3
8 months ago
CVE-2019-7069-POC preview

CVE-2019-7069-POC

GitHubcaelumisme/cve-2019-7069-poc

Python 3 exploit for Kibana < 6.6.1 RCE (CVE-2019-7609) via prototype pollution, with automatic version detection and optional reverse shell.

educationexploitationpayload-development+3
10 months ago
CVE-2020-6468-Chrome-Exploit preview

CVE-2020-6468-Chrome-Exploit

GitHubkiks7/cve-2020-6468-chrome-exploit

JavaScript-based exploit for Chrome V8 vulnerability CVE-2020-6468, with a d8 shell script and an HTML-based Chrome target.

exploitationpayload-developmentvulnerability-analysis+1
14 years ago
CVE-2025-55182_CVE-2025-66478 preview

CVE-2025-55182_CVE-2025-66478

GitHublincemorado97/cve-2025-55182_cve-2025-66478

Proof-of-concept exploit for critical RCE (CVSS 10.0) in Next.js/React Server Components via deserialization manipulation. Includes Python script for…

exploitationpayload-developmentpenetration-testing+2
8 months ago
CVE-2024-53900 preview

CVE-2024-53900

GitHubwww-spam/cve-2024-53900

Reproducible environment and PoC for CVE-2024-53900, a critical RCE in Mongoose via populate().match $where. Includes automated exploit script and…

educationexploitationpayload-development+3
1 year ago
CVE-2025-24801 preview

CVE-2025-24801

GitHubfatkz/cve-2025-24801

Proof-of-concept exploit for CVE-2025-24801, an LFI-to-RCE vulnerability in GLPI 10.0.17. Automates login, enables PHP uploads, and uploads a reverse…

exploitationpayload-developmentpenetration-testing+3
31 year ago
CVE-2024-25600 preview

CVE-2024-25600

GitHubr0otk3r/cve-2024-25600

Python-based exploit for CVE-2024-25600 targeting Bricks Builder WordPress plugin RCE. Automates nonce extraction, payload injection, and arbitrary…

exploitationinformation-gatheringpayload-development+3
1 year ago
CVE-2025-55182-Exploit preview

CVE-2025-55182-Exploit

GitHubselectarget/cve-2025-55182-exploit

Improved exploit script for CVE-2025-55182 React Server Components RCE vulnerability with manual multipart construction for reliable detection and…

exploitationpayload-developmentpenetration-testing+3
8 months ago
CVE-2024-40110 preview

CVE-2024-40110

GitHubabdurahmon3236/cve-2024-40110

Proof-of-concept script demonstrating unauthenticated remote code execution in Sourcecodester Poultry Farm Management System via the vulnerable…

code-analysisexploitationpayload-development+3
2 years ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubsahmsec/cve-2026-3844

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

exploitationpayload-developmentpenetration-testing+3
3 months ago
WSL_Payload_Builder preview

WSL_Payload_Builder

GitHubm1ddl3w4r3/wsl_payload_builder

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

payload-developmentpayload-generationpenetration-testing+1
729 months ago
vulnerable-next-js-poc preview

vulnerable-next-js-poc

GitHubkondukto-io/vulnerable-next-js-poc

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components via unsafe deserialization.…

educationexploitationpayload-development+3
58 months ago
jboss-autopwn preview

jboss-autopwn

GitHubgitcollect/jboss-autopwn

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

command-and-controlexploitationpayload-development+4
110 years ago
CVE-2020-7247-reproducer preview

CVE-2020-7247-reproducer

GitHubminhluannguyen/cve-2020-7247-reproducer

Docker-based environment to reproduce CVE-2020-7247 (OpenSMTPD) with a Python exploit script for arbitrary command execution and reverse shell via…

educationexploitationpayload-development+3
11 year ago
CVE-2021-3007-docker-poc preview

CVE-2021-3007-docker-poc

GitHubyunus-a1i/cve-2021-3007-docker-poc

Reproducible Proof-of-Concept for CVE-2021-3007 (Laminas/Zend HTTP deserialization RCE) with a standalone exploit script, Nuclei template, and…

educationexploitationpayload-development+3
8 months ago
CVE-2022-41082-POC preview

CVE-2022-41082-POC

GitHubbigherocenter/cve-2022-41082-poc

Post-authentication remote code execution exploit for Microsoft Exchange Server (CVE-2022-41082) with a PowerShell privilege escalation script for…

exploitationpayload-developmentpenetration-testing+3
13 years ago
CVE-2022-39197-RCE preview

CVE-2022-39197-RCE

GitHubthecryinggame/cve-2022-39197-rce

CVE-2022-39197 RCE POC

command-and-controlexploitationpayload-development+2
133 years ago
FuguHub-8.4-Authenticated-RCE-CVE-2024-27697 preview

FuguHub-8.4-Authenticated-RCE-CVE-2024-27697

GitHubsanjindedic/fuguhub-8.4-authenticated-rce-cve-2024-27697

Arbitrary Code Execution on FuguHub 8.4

command-and-controlexploitationpayload-development+5
102 years ago
Previous12345Next