Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
509 results
CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC preview

CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC

GitHubduc-nt/cve-2022-44268-imagemagick-arbitrary-file-read-poc

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

educationexploitationpayload-generation+3
275
3 years ago
Fudge preview

Fudge

GitHubdale-ruane/fudge

Hiding implants in HTML files

payload-generationphishingred-teaming+1
646 years ago
CVE-2017-8759 preview

CVE-2017-8759

GitHubbhdresh/cve-2017-8759

Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

educationexploitationpayload-generation+3
3127 years ago
CVE-2024-53677 preview

CVE-2024-53677

GitHubyangyanglo/cve-2024-53677

Proof-of-concept exploit for CVE-2024-53677 (S2-067), an Apache Struts2 file upload logic bypass enabling remote code execution via crafted filename…

exploitationpayload-generationpenetration-testing+2
31 year ago
eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE preview

eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE

GitHubfuzzlove/elabftw-1.8.5-entitycontroller-arbitrary-file-upload-rce

Exploit for eLabFTW 1.8.5 (CVE-2019-12185) enabling arbitrary file upload and remote code execution via EntityController. Generates a PHP shell in…

exploitationpayload-generationpenetration-testing+2
77 years ago
Better-CVE-2022-29464 preview

Better-CVE-2022-29464

GitHubjimidk/better-cve-2022-29464

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

exploitationpayload-generationpenetration-testing+3
54 years ago
-CVE-2014-6271-Shellshock-Remote-Command-Injection- preview

-CVE-2014-6271-Shellshock-Remote-Command-Injection-

GitHubfilipstudeny/-cve-2014-6271-shellshock-remote-command-injection-

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

exploitationpayload-generationpenetration-testing+3
3 years ago
LFISuite preview

LFISuite

GitHubd35m0nd142/lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

exploitationpayload-generationpenetration-testing+3
2.0k8 years ago
CVE-2023-26262 preview

CVE-2023-26262

GitHubistern/cve-2023-26262

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

code-analysisexploitationpayload-generation+3
3 years ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9626 days ago
backdoor-apk preview

backdoor-apk

GitHubdana-at-cp/backdoor-apk

backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have…

android-securityeducationexploit-frameworks+2
2.4k7 years ago
scaredycat preview

scaredycat

GitHubeudemonics/scaredycat

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

android-securityexploitationmobile-security+4
1710 years ago
CVE-2008-4654 preview

CVE-2008-4654

GitHubrnnsz/cve-2008-4654

PoC exploit generator for CVE-2008-4654, a stack-based buffer overflow in VLC Media Player via crafted .ty+ files. Generates malicious payload file…

binary-exploitationexploitationpayload-generation+2
5 years ago
CVE-2025-12973 preview

CVE-2025-12973

GitHubd0n601/cve-2025-12973

S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

code-analysisexploitationpayload-generation+3
9 months ago
Upload_Bypass preview

Upload_Bypass

GitHubsajibuu/upload_bypass

A simple tool for bypassing file upload restrictions.

exploitationpayload-generationpenetration-testing+2
9082 years ago
CVE-2023-24249-Exploit preview

CVE-2023-24249-Exploit

GitHubiduzzel/cve-2023-24249-exploit

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

educationexploitationpayload-generation+4
92 years ago
CVE-2026-56290_PoC preview

CVE-2026-56290_PoC

GitHubchiefyoru/cve-2026-56290_poc

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to…

exploitationpayload-generationpenetration-testing+2
1 month ago
CVE-2020-1938_Ghostcat-PoC preview

CVE-2020-1938_Ghostcat-PoC

GitHubabrewer251/cve-2020-1938_ghostcat-poc

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

exploitationinformation-gatheringpayload-generation+3
8 months ago
Previous12…29Next