Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
FsquirtCPLPoC preview

FsquirtCPLPoC

GitHubmhaskar/fsquirtcplpoc

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

binary-exploitationcommand-and-controlexploitation+5
121
8 months ago
CVE-2025-24071-msfvenom preview

CVE-2025-24071-msfvenom

GitHubfolks-iwd/cve-2025-24071-msfvenom

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

exploitationexploit-frameworkspassword-attacks+2
251 year ago
WinRAR-CVE-2023-38831 preview

WinRAR-CVE-2023-38831

GitHubxaitax/winrar-cve-2023-38831

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is…

exploitationexploit-frameworkspayload-generation+3
173 years ago
nate158g-m-w-n-l-p-d-a-o-e preview

nate158g-m-w-n-l-p-d-a-o-e

GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

exploit-frameworkspayload-generationpenetration-testing-frameworks+3
154 years ago
CVE-2025-61922-PoC preview

CVE-2025-61922-PoC

GitHubg0vguy/cve-2025-61922-poc

A simple, educational proof-of-concept script demonstrating the zero-click account takeover vulnerability in the PrestaShop Checkout module…

educationexploitationpayload-generation+3
118 months ago
CVE-2026-58457 preview

CVE-2026-58457

GitHubj4ck3lsyn-gen2/cve-2026-58457

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

command-and-controleducationexploitation+7
22 months ago
CVE-2022-36446-Webmin-RCE preview

CVE-2022-36446-Webmin-RCE

GitHubdarnabin/cve-2022-36446-webmin-rce

Authenticated remote code execution exploit for Webmin < 1.997 via the Software Package Updates module. Injects arbitrary commands as root through an…

command-and-controlexploitationpayload-generation+3
2 months ago
Rejetto-HFS-2.x-RCE-CVE-2024-23692 preview

Rejetto-HFS-2.x-RCE-CVE-2024-23692

GitHubpradeepboo/rejetto-hfs-2.x-rce-cve-2024-23692

Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)

exploitationpayload-generationpenetration-testing+3
12 years ago
cve-2025-59287 preview

cve-2025-59287

GitHubadel-hx0d/cve-2025-59287

Exploitation toolkit for CVE-2025-59287 RCE in WSUS. Includes AES payload encryption and an exploitation module for authorized penetration testing.

educationencryption-decryption-toolsexploitation+3
110 months ago
CVE-2022-44136-poc preview

CVE-2022-44136-poc

GitHubch35h1r3c47/cve-2022-44136-poc

Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with…

exploitationpayload-generationpenetration-testing+2
17 months ago
CVE-2024-26169-Detail-1 preview

CVE-2024-26169-Detail-1

GitHubkautilyagupt/cve-2024-26169-detail-1

Metasploit module for exploiting CVE-2017-11882 (MS Office Equation Editor vulnerability) using mshta.exe payload execution for remote code execution.

exploitationexploit-frameworkspayload-generation+3
8 years ago
CVE-2018-8174-msf preview

CVE-2018-8174-msf

GitHublikekabin/cve-2018-8174-msf

Metasploit module generating a malicious Word document to exploit CVE-2018-8174, a VBScript memory corruption vulnerability in Microsoft Office…

exploitationexploit-frameworkspayload-generation+3
8 years ago
FreePBX-Reverse-Shell-Module preview

FreePBX-Reverse-Shell-Module

GitHubh3x0v3rl0rd/freepbx-reverse-shell-module

Exploit module for FreePBX delivering a reverse shell payload to achieve remote command execution and persistent shell access, designed for…

exploitationpayload-generationpenetration-testing+3
5 years ago
CVE-2015-1397-Magento-Shoplift preview

CVE-2015-1397-Magento-Shoplift

GitHubwytchwulf/cve-2015-1397-magento-shoplift

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

ctfexploitationpayload-generation+3
2 years ago
WBCE-v1.6.3-Authenticated-RCE preview

WBCE-v1.6.3-Authenticated-RCE

GitHubswammers8/wbce-v1.6.3-authenticated-rce

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

exploitationpayload-generationremote-access-tool+1
1 year ago
CVE-2023-50564 preview
Archived

CVE-2023-50564

GitHubipuig/cve-2023-50564

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

exploitationpayload-generationreverse-engineering+2
2 years ago
CrossC2 preview

CrossC2

GitHubgloxec/crossc2

generate CobaltStrike's cross-platform payload

command-and-controlexploit-frameworkspayload-development+4
2.6k3 years ago
CVE-2018-8174-msf preview

CVE-2018-8174-msf

GitHub0x09al/cve-2018-8174-msf

CVE-2018-8174 - VBScript memory corruption exploit.

exploitationexploit-frameworkspayload-generation+3
1678 years ago
Previous123Next