Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
CVE-2024-54152 preview

CVE-2024-54152

GitHubmath-x-io/cve-2024-54152

PoC exploit for Angular Expressions sandbox escape (CVE-2024-54152) achieving RCE via malicious expression. Includes Docker environment and payload…

educationexploitationpayload-development+2
12
1 year ago
cve-2025-55182 preview

cve-2025-55182

GitHub0xpthree/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), demonstrating remote code execution in React Server Components through crafted Next-Action…

educationexploitationpayload-development+3
9 months ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
1 month ago
CVE-2020-7247-reproducer preview

CVE-2020-7247-reproducer

GitHubminhluannguyen/cve-2020-7247-reproducer

Docker-based environment to reproduce CVE-2020-7247 (OpenSMTPD) with a Python exploit script for arbitrary command execution and reverse shell via…

educationexploitationpayload-development+3
1 year ago
CVE-2018-12533 preview

CVE-2018-12533

GitHubllamaonsecurity/cve-2018-12533

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

exploitationlabs-practicepapers-research+3
95 years ago
WP-CVE-2016-10033 preview

WP-CVE-2016-10033

GitHubliusec/wp-cve-2016-10033

Docker-based lab environment for WordPress <= 4.6 remote code execution via PHPMailer (CVE-2016-10033), including PoC, webshell upload, and reverse…

exploitationlabs-practicepayload-development+3
19 years ago
CVE-2021-3007-docker-poc preview

CVE-2021-3007-docker-poc

GitHubyunus-a1i/cve-2021-3007-docker-poc

Reproducible Proof-of-Concept for CVE-2021-3007 (Laminas/Zend HTTP deserialization RCE) with a standalone exploit script, Nuclei template, and…

educationexploitationpayload-development+3
9 months ago
CVE-2023-32571-POC preview

CVE-2023-32571-POC

GitHubvert16x/cve-2023-32571-poc

Proof-of-concept exploit for CVE-2023-32571 demonstrating Dynamic Linq injection to achieve remote code execution, with a Docker-based lab…

code-analysiseducationexploitation+4
2 years ago
cve-2025-5025 preview

cve-2025-5025

GitHubkiphuong/cve-2025-5025

Proof-of-concept exploit for CVE-2025-5025, demonstrating the vulnerability with a Docker-based environment for testing and validation.

exploitationpayload-developmentpenetration-testing+2
1 year ago
viewstate-security-workshop preview

viewstate-security-workshop

GitHubirsdl/viewstate-security-workshop

This repository is for the Testing ASP.NET ViewState with YSoNet (YSoSerial.NET) workshop.

educationexploitationlabs-practice+5
258 months ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubeqstlab/cve-2026-21858

Ni8mare, n8n RCE

educationexploitationpayload-development+3
13 months ago
CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE- preview

CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-

GitHubdhananjayasj/cve-2025-24813-apache-tomcat-partial-put-deserialization-rce-

Proof-of-concept exploit for CVE-2025-24813, an unauthenticated RCE in Apache Tomcat via partial PUT and deserialization. Includes Docker lab for…

exploitationlabs-practicepayload-development+3
3 months ago
KindaRails2Shell preview

KindaRails2Shell

GitHub0xsha/kindarails2shell

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

exploitationlabs-practicepayload-development+4
31 month ago
CVE-2018-11776-Python-PoC preview

CVE-2018-11776-Python-PoC

GitHubhook-s3c/cve-2018-11776-python-poc

Working Python test and PoC for CVE-2018-11776, includes Docker lab

exploitationlabs-practicepayload-development+3
1238 years ago
CVE-2024-53900 preview

CVE-2024-53900

GitHubwww-spam/cve-2024-53900

Reproducible environment and PoC for CVE-2024-53900, a critical RCE in Mongoose via populate().match $where. Includes automated exploit script and…

educationexploitationpayload-development+3
1 year ago
CVE-2025-8625 preview

CVE-2025-8625

GitHubret0x2a/cve-2025-8625

Proof-of-concept exploit for CVE-2025-8625 targeting WordPress, with Docker-based isolated lab environment and demonstration web shell for…

educationexploitationlabs-practice+3
111 months ago
redis-cve-2025-62507 preview

redis-cve-2025-62507

GitHubgartonchan/redis-cve-2025-62507

Exploit scripts for CVE-2025-62507, a stack buffer overflow in Redis 8.2.0. Provides x86-64 and ARM64 ROP chain exploits with shellcode generation…

binary-exploitationcontainer-securitydebuggers+6
3 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubycseo-git/cve-2025-55182

a.k.a. React2Shell

code-analysiscontainer-securityctf+7
3 months ago
Previous12Next