Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
107 results
SMBRat preview

SMBRat

GitHuboperatorequals/smbrat

A Windows Remote Administration Tool in Visual Basic with UNC paths

command-and-controlexploitationlateral-movement+8
227 years ago
CVE-2025-26686-The-TCP-IP-Flaw-That-Opens-the-Gates preview

CVE-2025-26686-The-TCP-IP-Flaw-That-Opens-the-Gates

GitHubmrk336/cve-2025-26686-the-tcp-ip-flaw-that-opens-the-gates

A critical RCE vulnerability in Windows TCP/IP stack (CVE-2025-26686) leaves sensitive memory unlocked, allowing remote attackers to hijack systems.…

binary-exploitationeducationexploitation+4
321 year ago
R2C-CVE-2025-55182-66478 preview

R2C-CVE-2025-55182-66478

GitHubcybertechajju/r2c-cve-2025-55182-66478

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+8
249 months ago
pyc2 preview

pyc2

GitHubr00k5a58/pyc2

simple c2 written in python to demonstrate security concepts

command-and-controleducationnetwork-security+3
138 years ago
CVE-2025-2304-POC preview

CVE-2025-2304-POC

GitHubd3vn0mi/cve-2025-2304-poc

Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.

educationexploitationpayload-generation+4
104 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubk3ystr0k3r/cve-2026-24061

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

authenticationauthentication-authorizationcommand-and-control+8
33 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubtausifzaman/cve-2026-3844

PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.

educationexploitationpayload-generation+4
35 months ago
OpenSTAManager_RCE_Exploit-CVE-2026-38751- preview

OpenSTAManager_RCE_Exploit-CVE-2026-38751-

GitHubhackthem/openstamanager_rce_exploit-cve-2026-38751-

OpenSTAManager RCE Exploit (CVE-2026-38751)

exploitationpayload-generationpenetration-testing+4
12 months ago
CVE-2025-28915 preview

CVE-2025-28915

GitHubnxploited/cve-2025-28915

WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2024-50986 preview

CVE-2024-50986

GitHubriftsandroses/cve-2024-50986

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

binary-exploitationexploitationpayload-generation+4
1 year ago
TinkererShell preview
Archived

TinkererShell

GitHub4n4nk3/tinkerershell

A simple python reverse shell written just for fun.

command-and-controldata-exfiltrationdns-analysis+8
623 years ago
CVE-2020-16898 preview
Archived

CVE-2020-16898

GitHubzephrfish/cve-2020-16898

HoneyPoC 2.0: Proof-of-Concept (PoC) script to exploit IPv6 (CVE-2020-16898).

educationexploitationnetwork-security+3
221 month ago
rpi-hunter preview

rpi-hunter

GitHubbusescanfly/rpi-hunter

Auto discover and exploit LAN raspberry pi's

exploitationinformation-gatheringnetwork-security+2
1082 years ago
MS09-050 preview

MS09-050

GitHubbytejmp/ms09-050

Python exploit for MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow, with vulnerability scanner, arch auto-detection, and x86/x64 reverse…

exploitationinformation-gatheringnetwork-security+7
8 days ago
watchTowr-vs-JunosEvolved-CVE-2026-21902 preview

watchTowr-vs-JunosEvolved-CVE-2026-21902

GitHubwatchtowrlabs/watchtowr-vs-junosevolved-cve-2026-21902

Generates detection artifacts for CVE-2026-21902 on Juniper Junos Evolved, enabling verification of unauthenticated remote code execution via command…

exploitationinformation-gatheringnetwork-security+4
46 months ago
CVE-2026-64638-POC preview

CVE-2026-64638-POC

GitHubimbas007/cve-2026-64638-poc

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

exploitationinformation-gatheringpayload-generation+4
111 month ago
CVE-2026-48908-by-yora preview

CVE-2026-48908-by-yora

GitHubyora1928/cve-2026-48908-by-yora

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

exploitationinformation-gatheringpayload-generation+7
21 month ago
Previous123456Next