Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1675 results
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+7
3.9k
2 months ago
WordPress_4.9.8_RCE_POC preview

WordPress_4.9.8_RCE_POC

GitHubbrianwrf/wordpress_4.9.8_rce_poc

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

code-analysisexploitationpayload-development+3
737 years ago
0-click-RCE-Exploit-for-CVE-2024-10924 preview

0-click-RCE-Exploit-for-CVE-2024-10924

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-10924

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

authenticationexploitationpayload-development+4
147 months ago
react2shell-CVE-2025-55182-poc preview

react2shell-CVE-2025-55182-poc

GitHubjoelvaiju/react2shell-cve-2025-55182-poc

a simple react2shell poc with basic waf bypass

exploitationpayload-developmentpenetration-testing+3
38 months ago
CVE-2025-24813-POC preview

CVE-2025-24813-POC

GitHubnamelesssaint8/cve-2025-24813-poc

A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).

exploitationpayload-developmentpenetration-testing+3
11 year ago
Webmin_Exploit_reverse_shell preview
Archived

Webmin_Exploit_reverse_shell

GitHubbytereaper77/webmin_exploit_reverse_shell

A simple C-based vulnerability in Webmin versions 1.890 to 1.920

binary-exploitationexploitationpayload-development+4
21 year ago
CVE-2016-3714 preview

CVE-2016-3714

GitHubhood3drob1n/cve-2016-3714

ImaegMagick Code Execution (CVE-2016-3714)

exploitationpayload-developmentpenetration-testing+3
7010 years ago
CVE-2018-10933-POC preview

CVE-2018-10933-POC

GitHubsambiyal/cve-2018-10933-poc

libSSH bypass

exploitationpayload-developmentpenetration-testing+2
7 years ago
PoC-for-CVE-2020-28948-CVE-2020-28949 preview

PoC-for-CVE-2020-28948-CVE-2020-28949

GitHubjinhao-l/poc-for-cve-2020-28948-cve-2020-28949
exploitationpayload-developmentpenetration-testing+3
3 years ago
CVE-2021-3060 preview

CVE-2021-3060

GitHubanmolksachan/cve-2021-3060

CVE-2021-3060

command-and-controlexploitationpayload-development+3
2 years ago
CVE-2024-4157-SSRF-RCE-Reverse-Shell preview

CVE-2024-4157-SSRF-RCE-Reverse-Shell

GitHubch4os1/cve-2024-4157-ssrf-rce-reverse-shell

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

command-and-controlexploitationpayload-development+3
11 months ago
CVE-2023-27163-POC preview

CVE-2023-27163-POC

GitHublukehebe/cve-2023-27163-poc

CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}.…

exploitationpayload-developmentpenetration-testing+3
21 year ago
CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065 preview

CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065

GitHubsimoesctt/ctt-exchange-rce-v1.0---microsoft-exchange-exploit-cvss-10.0-critical-cve-2021-26855-cve-2021-27065

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

command-and-controlexploitationexploit-frameworks+7
16 months ago
ProxyLogon-CVE-2021-26855-metasploit preview

ProxyLogon-CVE-2021-26855-metasploit

GitHubtaroballzchen/proxylogon-cve-2021-26855-metasploit

CVE-2021-26855 proxyLogon metasploit exploit script

exploit-frameworkspayload-developmentpenetration-testing+3
45 years ago
CVE-2024-38472 preview

CVE-2024-38472

GitHubabdurahmon3236/cve-2024-38472
command-and-controlexploit-frameworkslateral-movement+6
42 years ago
CVE-2024-41651 preview

CVE-2024-41651

GitHubfckroun/cve-2024-41651

CVE-2024-41651

exploitationpayload-developmentpenetration-testing+3
12 years ago
Exploits preview

Exploits

GitHubkmkz/exploits

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

command-and-controlcontainer-escapeeducation+6
21719 days ago
JNDI-Injection-Exploit-Plus preview

JNDI-Injection-Exploit-Plus

GitHubcckuailong/jndi-injection-exploit-plus

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…

exploit-frameworkspayload-developmentpenetration-testing+2
8802 years ago
Previous12…94Next