Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
233 results
OpenPLC-CVE-2021-31630-RCE preview

OpenPLC-CVE-2021-31630-RCE

GitHubmachevalia/openplc-cve-2021-31630-rce

Python 3.13+ proof-of-concept exploit for CVE-2021-31630, enabling authenticated remote code execution on OpenPLC v3 via malicious hardware layer…

educationexploitationpayload-development+3
3
1 year ago
exploit-CVE-2025-49113 preview

exploit-CVE-2025-49113

GitHubrasool13x/exploit-cve-2025-49113

Proof-of-concept PHP exploit for CVE-2025-49113, a remote code execution vulnerability in Roundcube Webmail via PHP object deserialization in the…

educationexploitationpayload-development+3
31 year ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubeqstlab/cve-2026-5027

Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal

educationexploitationpayload-development+3
35 months ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
2 months ago
CVE-2026-22738 preview

CVE-2026-22738

GitHubrockmelodies/cve-2026-22738

SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

educationexploitationpayload-development+3
25 months ago
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection preview

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

GitHubhunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

Proof-of-concept exploit for CVE-2026-58116 demonstrating remote code execution in LLaMA-Factory WebUI via trust_remote_code model path injection.…

code-analysisctfeducation+5
2 months ago
ms08-067.py preview

ms08-067.py

GitHubbinracer/ms08-067.py

This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic…

educationexploitationpayload-development+3
310 months ago
CVE-2012-1823 preview

CVE-2012-1823

GitHubk3ystr0k3r/cve-2012-1823

CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)

educationexploitationpayload-development+3
2 months ago
CVE-2025-49091-Gajim-RCE preview

CVE-2025-49091-Gajim-RCE

GitHubthefreestyleresearcher/cve-2025-49091-gajim-rce

Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.

educationexploitationpayload-development+2
1 month ago
CVE-2026-35194 preview

CVE-2026-35194

GitHubdexsemon/cve-2026-35194

Proof-of-concept exploit and Docker lab for CVE-2026-35194, an Apache Flink SQL code injection enabling remote code execution on TaskManagers via the…

educationexploitationlabs-practice+5
2 months ago
CVE-2026-38751-OpenSTAManager-Arbitrary-File-Upload-PoC preview

CVE-2026-38751-OpenSTAManager-Arbitrary-File-Upload-PoC

GitHubmkps/cve-2026-38751-openstamanager-arbitrary-file-upload-poc

This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an…

educationexploitationpayload-development+3
2 months ago
CVE-2026-33937 preview

CVE-2026-33937

GitHubeqstlab/cve-2026-33937

Handlebars.js AST Injection Remote Code Execution Vulnerability

educationexploitationlabs-practice+5
25 months ago
Spring4Shell-POC preview

Spring4Shell-POC

GitHubprinceh4k/spring4shell-poc

Proof of Concept for exploiting the CVE-2022-22965 (Spring4Shell) vulnerability in an isolated environment, with Remote Code Execution (RCE)…

educationexploitationlabs-practice+4
1 month ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcyberleelawat/cve-2025-55182

A critical Remote Code Execution (RCE) vulnerability affecting the React Server Components (RSC) implementation within multiple packages including.

educationexploitationinformation-gathering+5
13 months ago
CVE-2023-6553-RCE-Exploit preview

CVE-2023-6553-RCE-Exploit

GitHub0x00phantom-hat/cve-2023-6553-rce-exploit

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the…

educationexploitationpayload-development+3
25 months ago
CVE-2024-46986 preview

CVE-2024-46986

GitHubvidura2/cve-2024-46986

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

educationexploitationpayload-development+3
32 years ago
bassmaster-rce preview

bassmaster-rce

GitHubmaximilianmarx/bassmaster-rce

Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.

code-analysiseducationexploitation+3
35 years ago
CVE-2026-54088-poc preview

CVE-2026-54088-poc

GitHubsaku0512/cve-2026-54088-poc

Proof-of-concept exploit for CVE-2026-54088, a pre-authentication OS command injection in File Browser <=2.63.5. Demonstrates shell injection via…

command-and-controleducationexploitation+4
13 months ago
Previous1…456…13Next