Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
CVE-2026-23744-MCPJAM-RCE-exploit preview

CVE-2026-23744-MCPJAM-RCE-exploit

GitHubdahalsamir/cve-2026-23744-mcpjam-rce-exploit

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an…

exploitationpayload-generationpenetration-testing+2
2 months ago
CVE-2026-2586 preview

CVE-2026-2586

GitHubdeepsecurityresearch/cve-2026-2586

Authenticated EL injection exploit for GlassFish/Payara admin console enabling remote command execution via crafted parameters in the virtual server…

exploitationpayload-generationpenetration-testing+3
22 months ago
CSRF-exploit-generator preview

CSRF-exploit-generator

GitHubjenderal92/csrf-exploit-generator

The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.

payload-generationpenetration-testingweb-application-exploitation+1
3 months ago
CaA preview

CaA

GitHuboverspace-labs/caa

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…

fuzzinginformation-gatheringpayload-generation+2
1.5k3 months ago
cerebro-red-v2 preview

cerebro-red-v2

GitHubleviticus-triage/cerebro-red-v2

CEREBRO-RED v2: Advanced LLM Red Team Research Platform with PAIR Algorithm and LLM-as-a-Judge Evaluation

adversarial-attackai-securitydynamic-analysis-sandboxing+8
165 months ago
MassExploit-CVE-2024-4577 preview

MassExploit-CVE-2024-4577

GitHubcirqueiradev/massexploit-cve-2024-4577

CVE-2024-4577 Mass Scanner & Exploit Tool

exploitationpayload-generationpenetration-testing+3
59 months ago
CVE-2022-25765 preview

CVE-2022-25765

GitHublowercasenumbers/cve-2022-25765

Python PoC exploit for CVE-2022-25765, a critical command injection in PDFKit. Generates a reverse shell via unsanitized URL parameters passed to…

command-and-controlexploitationpayload-generation+3
9 months ago
CVE-2016-10033 preview

CVE-2016-10033

GitHubalexander47777/cve-2016-10033

Proof-of-concept exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer, demonstrating injection of additional sendmail…

educationexploitationpayload-generation+3
1 year ago
CVE-2025-6860 preview
Archived

CVE-2025-6860

GitHubbytereaper77/cve-2025-6860

A proof‑of‑concept command‑line tool in C for detecting the SQL injection vulnerability .

exploitationpayload-generationpenetration-testing+2
21 year ago
CVE-2019-0232_tomcat_cgi_exploit preview

CVE-2019-0232_tomcat_cgi_exploit

GitHubx3m1sec/cve-2019-0232_tomcat_cgi_exploit

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

educationexploitationpayload-generation+3
1 year ago
CVE-2024-53677 preview

CVE-2024-53677

GitHubyangyanglo/cve-2024-53677

Proof-of-concept exploit for CVE-2024-53677 (S2-067), an Apache Struts2 file upload logic bypass enabling remote code execution via crafted filename…

exploitationpayload-generationpenetration-testing+2
31 year ago
donut preview

donut

GitHubthewover/donut

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

exploitationids-ips-evasionmemory-forensics+7
4.7k1 year ago
CVE-2023-24078 preview

CVE-2023-24078

GitHubag-rodriguez/cve-2023-24078

Proof-of-concept exploit for CVE-2023-24078, providing a reverse shell with configurable LHOST, LPORT, RHOST, and RPORT parameters for penetration…

exploitationpayload-generationpenetration-testing+2
2 years ago
ClearML-CVE-2024-24590 preview

ClearML-CVE-2024-24590

GitHuboxydev2/clearml-cve-2024-24590

Proof of concept for CVE-2024-24590

ai-securityexploitationpayload-generation+3
62 years ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubmanuelinfosec/cve-2024-4577

Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.

command-and-controlexploitationpayload-generation+3
92 years ago
CVE-2024-29375 preview

CVE-2024-29375

GitHubismailcemunver/cve-2024-29375

Proof-of-concept for CSV injection in Addactis IBNRS 3.10.3.107, demonstrating Excel formula injection leading to OS command execution via crafted…

educationexploitationpayload-generation+2
2 years ago
CVE-2023-0099-exploit preview

CVE-2023-0099-exploit

GitHubamirzargham/cve-2023-0099-exploit

simple urls < 115 - Reflected XSS

exploitationpayload-generationpenetration-testing+3
62 years ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
Previous12Next