Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
844 results
CTT-Mailpit-RCE-v1.0---Temporal-Resonance-Mail-Server-Takeover preview

CTT-Mailpit-RCE-v1.0---Temporal-Resonance-Mail-Server-Takeover

GitHubsimoesctt/ctt-mailpit-rce-v1.0---temporal-resonance-mail-server-takeover

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

command-and-controlexploitationmalware-analysis+5
8 months ago
react2shell-interactive preview

react2shell-interactive

GitHubnathanj60/react2shell-interactive

CVE-2025-55182 Interactive PoC - React Server Components RCE - Educational Security Research

command-and-controleducationexploitation+5
10 months ago
CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit preview

CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit

GitHubsimoesctt/ctt-proxylogon-rce-v1.0---convergent-time-theory-enhanced-microsoft-exchange-exploit

An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving…

command-and-controldata-exfiltrationexploitation+9
8 months ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubr0otk3r/cve-2025-3248

Scanner and exploit for CVE-2025-3248, an unauthenticated RCE in Langflow AI. Includes a vulnerability checker and a reverse shell payload generator…

command-and-controlexploitationpayload-development+5
11 year ago
Log4Shell-PoC preview

Log4Shell-PoC

GitHubjosemariamicoli/log4shell-poc

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

command-and-controleducationexploitation+6
8 months ago
CVE-2022-31199 preview

CVE-2022-31199

GitHubdeveloperfred/cve-2022-31199

Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload…

command-and-controleducationexploitation+5
10 months ago
CVE-2019-9624 preview

CVE-2019-9624

GitHubx0rbeexd/cve-2019-9624

Authenticated RCE for Webmin 1.9.0

command-and-controlexploitationpayload-development+3
9 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubj4ck3lsyn-gen2/cve-2025-55182

A simple toolkit to validate, exploit & gain an interactive shell via the react2Shell Next.js RCE.

command-and-controleducationexploitation+5
6 months ago
CVE-2025-66478 preview

CVE-2025-66478

GitHubrhyru9/cve-2025-66478

Proof-of-concept exploit for CVE-2025-66478, demonstrating remote code execution in Next.js via crafted multipart requests with prototype pollution.

command-and-controlexploitationpayload-development+3
10 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubgrejh0t/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical unauthenticated RCE in React Server Components via unsafe deserialization in…

command-and-controlexploitationpayload-development+3
9 months ago
CVE-2022-31491 preview

CVE-2022-31491

GitHubready2disclose/cve-2022-31491

CVE-2022-31491

command-and-controlexploitationexploit-frameworks+4
6 months ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubscroollocker/cve-2025-49132

Python exploit for CVE-2025-49132, enabling unauthenticated remote code execution on Pterodactyl Panel via crafted locale and namespace parameters.

command-and-controlexploitationpayload-development+3
7 months ago
CVE-2022-25226 preview

CVE-2022-25226

GitHubkrill-x7/cve-2022-25226

Python exploit script for ThinVNC 1.0b1 authentication bypass (CVE-2022-25226) that chains unauthenticated /cmd endpoint access with AMSI bypass and…

authenticationcommand-and-controleducation+4
11 year ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubuserb1ank/cve-2021-31630

Exploit for CVE-2021-31630 in OpenPLC, providing a Python script and manual steps to achieve remote code execution via malicious ST file upload and…

command-and-controlexploitationpayload-development+3
0 years ago
CVE-2025-32433-exploit preview

CVE-2025-32433-exploit

GitHubl1nuxkid/cve-2025-32433-exploit

Python-based exploit for CVE-2025-32433 with netcat listener integration for remote shell access and payload delivery.

command-and-controlexploitationpayload-development+3
11 months ago
Samba-Exploit-CVE-2007-2447 preview

Samba-Exploit-CVE-2007-2447

GitHubnulltrace1336/samba-exploit-cve-2007-2447

Step-by-step guide to exploiting Samba 3.0.20 (CVE-2007-2447) using Metasploit, including Nmap scanning, payload setup, and reverse shell execution.

command-and-controlexploitationexploit-frameworks+3
9 months ago
cve-2025-62726-malicious-repo preview

cve-2025-62726-malicious-repo

GitHubmuzyli/cve-2025-62726-malicious-repo

cve-2025-62726-malicious-repo

command-and-controlexploitationpayload-development+3
10 months ago
CVE-2026-6279 preview

CVE-2026-6279

GitHubxxconi/cve-2026-6279

CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode…

command-and-controlexploitationpayload-development+4
3 months ago
Previous1…44454647Next