Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
CVE-2026-33310 preview

CVE-2026-33310

GitHubredyank/cve-2026-33310

Proof-of-concept demonstrating command injection via shell() expansion in parameter defaults of Intake catalogs, with exploit YAML and reproduction…

command-and-controlexploitationpayload-generation+2
6 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubkernelzeroday/cve-2026-29000

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

authentication-authorizationexploitationpayload-generation+5
87 months ago
ThreadlessInject preview

ThreadlessInject

GitHubccob/threadlessinject

Threadless Process Injection using remote function hooking.

adversarial-attackpayload-developmentpayload-generation+4
8222 years ago
KeeFarceReborn preview

KeeFarceReborn

GitHubd3lb3/keefarcereborn

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

data-exfiltrationpassword-attackspayload-generation+3
2993 years ago
Pluck-CMS-Stored-XSS---Installation preview

Pluck-CMS-Stored-XSS---Installation

GitHubsromanhu/pluck-cms-stored-xss---installation

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

payload-generationpenetration-testingred-teaming+3
3 years ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

command-and-controlexploitationpayload-generation+5
52 months ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubxmqaq/cve-2022-22963

CVE-2022-22963-poc

exploitationpayload-generationpenetration-testing+3
13 months ago
WPS-CVE-2022-24934 preview

WPS-CVE-2022-24934

GitHubmagicpipersec/wps-cve-2022-24934

PoC exploit server for CVE-2022-24934 that delivers a malicious payload via a fake WPS Update Server, targeting the wpsupdate.exe process for…

exploitationpayload-generationpenetration-testing+3
54 years ago
Unauthenticated-RCE-FUXA-CVE-2023-33831 preview

Unauthenticated-RCE-FUXA-CVE-2023-33831

GitHubrodolfomarianocy/unauthenticated-rce-fuxa-cve-2023-33831

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

exploitationpayload-generationpenetration-testing+4
131 year ago
MSHTML-CVE-2021-40444 preview

MSHTML-CVE-2021-40444

GitHubmetehangenel/mshtml-cve-2021-40444

Automated exploit for CVE-2021-40444 (MSHTML remote code execution) with DLL compilation and deployment via a single bash script.

exploitationpayload-generationpenetration-testing+2
5 years ago
CVE-2024-28397-Exploit-Automation preview

CVE-2024-28397-Exploit-Automation

GitHubl1337xi/cve-2024-28397-exploit-automation

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

ctfeducationexploitation+3
210 months ago
toxssin preview

toxssin

GitHubt3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

exploitationinformation-gatheringpayload-generation+4
1.5k1 year ago
Remot3d preview

Remot3d

GitHubmakiraid/remot3d

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

information-gatheringpayload-generationpenetration-testing+3
187 years ago
Exploit-CVE-2021-21086 preview

Exploit-CVE-2021-21086

GitHubinfobyte/exploit-cve-2021-21086

Python-based exploit for CVE-2021-21086 in Adobe Acrobat Reader DC, generating malicious PDFs with shellcode execution via crafted font charstrings.

binary-exploitationexploitationpayload-generation+3
264 years ago
CVE-2022-45701 preview

CVE-2022-45701

GitHubgeniuszly/cve-2022-45701

it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script…

educationexploitationiot-security+6
52 years ago
CVE-2013-2729 preview

CVE-2013-2729

GitHubfeliam/cve-2013-2729

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

binary-exploitationexploitationfuzzing+3
246 years ago
CVE-2022-42889-Text4Shell-POC preview

CVE-2022-42889-Text4Shell-POC

GitHubalealeluyah/cve-2022-42889-text4shell-poc

This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id:…

exploitationpayload-generationpenetration-testing+2
133 years ago
CVE-2022-4616-POC preview

CVE-2022-4616-POC

GitHubahanel13/cve-2022-4616-poc

This Python script aids in exploiting CVE-2022-46169 by automating payload delivery and response handling. It starts an HTTP server, listens for…

educationexploitationpayload-generation+2
3 years ago
Previous123Next