Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
151 results
CVE-2025-24813 preview

CVE-2025-24813

GitHubshivshantp/cve-2025-24813

Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC

educationexploitationlabs-practice+5
61 year ago
reverse-shell-generator preview

reverse-shell-generator

GitHub0dayctf/reverse-shell-generator

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

ctfexploitationpayload-development+6
4.1k5 months ago
pocsuite3 preview

pocsuite3

GitHubknownsec/pocsuite3

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

exploit-frameworkspayload-developmentpenetration-testing+2
3.9k1 year ago
metasploit_in_termux preview

metasploit_in_termux

GitHubgushmazuko/metasploit_in_termux

Install and run Metasploit Framework 6 on Android via Termux with automated setup, payload generation (msfvenom), and full msfconsole access for…

android-securityexploit-frameworksmobile-security+2
2.1k1 year ago
Spring4Shell-POC preview

Spring4Shell-POC

GitHublunasec-io/spring4shell-poc

This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).

exploitationlabs-practicepayload-development+4
1064 years ago
CVE-2013-2028-Exploit preview

CVE-2013-2028-Exploit

GitHubvanivamshi/cve-2013-2028-exploit

Docker-based lab and Python exploit for CVE-2013-2028, an Nginx 1.3.9 chunked-parser integer overflow, covering canary recovery, mprotect, and…

binary-exploitationeducationexploitation+6
16 days ago
CVE-2026-60137-and-CVE-2026-63030 preview

CVE-2026-60137-and-CVE-2026-63030

GitHubivanesk315/cve-2026-60137-and-cve-2026-63030

Docker-based WordPress lab reproducing CVE-2026-60137 and CVE-2026-63030 pre-auth RCE, with a Python PoC exploit for SQLi, privilege escalation, and…

educationexploitationlabs-practice+6
19 days ago
cpiopwn preview

cpiopwn

GitHubfangqyi/cpiopwn

ACE poc exploit for glibc cpio 2.13 through mmap chunk metadata curruption (CVE-2021-38185)

binary-exploitationeducationexploitation+3
55 years ago
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
21 month ago
CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept preview

CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

GitHubkra1t0/cve-2025-33053-webdav-rce-poc-and-c2-concept

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

command-and-controleducationexploitation+5
31 year ago
CVE-2022-22965-Spring4Shell preview

CVE-2022-22965-Spring4Shell

GitHubjakabakos/cve-2022-22965-spring4shell

PoC and exploit for CVE-2022-22965 Spring4Shell

educationexploitationpayload-development+3
23 years ago
metabase-cve-2023-38646 preview

metabase-cve-2023-38646

GitHubkushiro45/metabase-cve-2023-38646

Repo contains the PoC and steps to reproduce cve 2023-38646

exploitationpayload-developmentpenetration-testing+3
2 months ago
CVE-2024-37054-MLflow-RCE preview

CVE-2024-37054-MLflow-RCE

GitHubniteeshpujari/cve-2024-37054-mlflow-rce

NiteeshPujari/CVE-2024-37054, This repository contains a Proof of Concept (PoC) a critical deserialization vulnerability in MLflow that allows for…

educationexploitationpayload-development+3
31 year ago
CVE-2025-55182-Dockerized preview

CVE-2025-55182-Dockerized

GitHubclevernyyyy/cve-2025-55182-dockerized

Dockerized proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components via prototype pollution, with automated exploit scripts and…

educationexploitationlabs-practice+3
17 months ago
cve-2026-87902-wordpress-lfi-lab preview

cve-2026-87902-wordpress-lfi-lab

GitHubdinosn/cve-2026-87902-wordpress-lfi-lab

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional…

educationexploitationlabs-practice+7
36 days ago
CVE-2019-11043 preview

CVE-2019-11043

GitHubthemiddleblue/cve-2019-11043

(PoC) Python version of CVE-2019-11043 exploit by neex

exploitationpayload-developmentpenetration-testing+3
1476 years ago
CVE-2026-25253 preview

CVE-2026-25253

GitHubeqstlab/cve-2026-25253

OpenClaw Authentication Token Exfiltration

exploitationpayload-developmentpenetration-testing+3
24 months ago
CVE-2026-47670 preview

CVE-2026-47670

GitHuberror-inside/cve-2026-47670

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

code-analysiseducationexploitation+4
3 months ago
Previous1…456…9Next