Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
marshalsec preview

marshalsec

GitHubmbechler/marshalsec

Java deserialization vulnerability exploitation tool with payload generators for multiple marshallers (Jackson, XStream, SnakeYAML) and JNDI…

educationexploitationpapers-research+5
3.7k
1 year ago
CVE-2026-23744-MCPJam-Exploit preview

CVE-2026-23744-MCPJam-Exploit

GitHubcerberusmrxi/cve-2026-23744-mcpjam-exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

command-and-controleducationexploitation+4
81 month ago
Hollow preview

Hollow

GitHubchaelsoo/hollow

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

binary-exploitationencryption-decryption-toolsexploitation+7
1012 months ago
Commander preview

Commander

GitHubvoukatas/commander

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

command-and-controlencryption-decryption-toolspayload-development+3
632 years ago
CVE-2022-31814 preview

CVE-2022-31814

GitHubarunhatter/cve-2022-31814

This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list…

exploitationpayload-developmentpenetration-testing+3
2 years ago
cve-2022-28944 preview

cve-2022-28944

GitHubgar-re/cve-2022-28944

Proof-of-concept exploit for unauthenticated remote code execution in EMCO Software products via DNS spoofing and malicious update injection.

command-and-controlexploitationpayload-development+3
43 years ago
CVE-2022-21350 preview

CVE-2022-21350

GitHubhktalent/cve-2022-21350

Exploit toolkit for CVE-2022-21350 targeting Oracle WebLogic T3 protocol with payload generation, LDAP/HTTP servers, and support for multiple JDK…

command-and-controlexploitationpayload-development+3
32 years ago
SpookFlare preview
Archived

SpookFlare

GitHubhlldz/spookflare

Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.

exploit-frameworkspayload-developmentpayload-generation+1
9417 years ago
CVE-2026-40487 preview

CVE-2026-40487

GitHubastaruf/cve-2026-40487

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

exploitationpayload-developmentpenetration-testing+3
34 months ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubsaladin0x1/cve-2025-53770

Proof-of-concept exploit toolkit for SharePoint ToolPane RCE (CVE-2025-53770) with scanner, payload analysis, and multiple exploitation methods for…

authenticationeducationexploitation+5
40 years ago
CVE-2026-5718 preview

CVE-2026-5718

GitHubxxconi/cve-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

code-analysisexploitationpayload-development+5
3 months ago
ditto preview

ditto

GitHubairbus-cert/ditto

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

code-analysismalware-analysispayload-development+2
4010 days ago
Weblogic_Wsat_RCE preview

Weblogic_Wsat_RCE

GitHubkbsec/weblogic_wsat_rce

POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this…

educationexploitationpayload-development+3
47 years ago
PoC-RCE-CVE-2025-55182 preview

PoC-RCE-CVE-2025-55182

GitHubilixm/poc-rce-cve-2025-55182

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

command-and-controlexploitationinformation-gathering+7
8 months ago
PrestaShop-CVE-2018-19126 preview

PrestaShop-CVE-2018-19126

GitHubfarisv/prestashop-cve-2018-19126

PrestaShop (1.6.x <= 1.6.1.23 or 1.7.x <= 1.7.4.4) Back Office Remote Code Execution (CVE-2018-19126)

educationexploitationpayload-development+3
397 years ago
CVE-2021-35211 preview

CVE-2021-35211

GitHubbishopfox/cve-2021-35211

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

binary-exploitationexploitationexploit-frameworks+6
394 years ago
ezsploit preview

ezsploit

GitHubrand0m1ze/ezsploit

Linux bash script automation for metasploit

command-and-controlexploit-frameworkspayload-development+5
26910 years ago
langflow-rce-exploit preview

langflow-rce-exploit

GitHub0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

command-and-controlexploitationpayload-development+8
71 year ago
Previous123Next