Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
477 results
Prestashop-CVE-2024-34716 preview

Prestashop-CVE-2024-34716

GitHub0xdtc/prestashop-cve-2024-34716

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

exploitationpayload-generationpenetration-testing+3
11 year ago
SillyRAT preview

SillyRAT

GitHubhash3lizer/sillyrat

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

command-and-controlpayload-generationpost-exploitation+1
9393 years ago
pupy preview
Archived

pupy

GitHubn1nj4sec/pupy

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

android-securitycommand-and-controllateral-movement+5
9.0k2 years ago
CVE-2023-4220-exploit preview

CVE-2023-4220-exploit

GitHubpr1or95/cve-2023-4220-exploit

Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en…

exploitationpayload-generationpenetration-testing+3
11 year ago
LFISuite preview

LFISuite

GitHubd35m0nd142/lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

exploitationpayload-generationpenetration-testing+3
2.0k8 years ago
pwncat preview

pwncat

GitHubcytopia/pwncat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

command-and-controlids-ips-evasionlateral-movement+7
2.0k4 years ago
RSPET preview

RSPET

GitHubpanagiks/rspet

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

command-and-controlexploitationpayload-generation+4
2638 years ago
through_the_wire preview

through_the_wire

GitHubjbaines-r7/through_the_wire

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

command-and-controlexploitationpayload-generation+3
1734 years ago
cve-2018-1273 preview

cve-2018-1273

GitHubjas502n/cve-2018-1273

Python-based exploit for CVE-2018-1273 (Spring Data Commons RCE) with interactive command shell and HTTP POST payload injection for penetration…

command-and-controlexploitationpayload-generation+3
587 years ago
CVE-2022-21587-POC preview

CVE-2022-21587-POC

GitHubhieuminhnv/cve-2022-21587-poc

Proof-of-concept exploit for CVE-2022-21587 targeting Oracle E-Business Suite with file overwrite and shell creation capabilities.

exploitationpayload-generationpenetration-testing+2
153 years ago
CVE-2023-50643 preview

CVE-2023-50643

GitHubgiovannipajeu1/cve-2023-50643

Automated exploit for CVE-2023-50643 targeting Evernote macOS via RunAsNode and enableNodeClilnspectArguments to achieve remote code execution and…

binary-exploitationexploitationpayload-generation+3
82 years ago
cve-2025-32433 preview

cve-2025-32433

GitHub0xpthree/cve-2025-32433

Python exploit for CVE-2025-32433 targeting Erlang OTP SSH server. Sends crafted SSH packets to open a reverse shell and gain root access.

command-and-controlexploitationpayload-generation+3
61 year ago
CVE-2026-38751 preview

CVE-2026-38751

GitHubwhy-shell/cve-2026-38751

Authenticated remote code execution exploit for OpenSTAManager via unvalidated ZIP upload, providing reverse shell and interactive webshell…

educationexploitationpayload-generation+3
2 months ago
cve-2026-23744 preview

cve-2026-23744

GitHubrohit-sundar/cve-2026-23744

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated RCE in MCPJam Inspector. Provides reverse shell and command execution via a…

command-and-controleducationexploitation+6
2 months ago
CVE-2022-22909 preview

CVE-2022-22909

GitHubkaal18/cve-2022-22909

Python-based exploit for Hotel Druid 3.0.3 Remote Code Execution (CVE-2022-22909). Injects PHP payloads via room names to achieve command execution…

exploitationpayload-generationpenetration-testing+3
24 years ago
CVE-2025-6440-Poc-Exploit preview

CVE-2025-6440-Poc-Exploit

GitHubm2hcz/cve-2025-6440-poc-exploit

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

exploitationpayload-generationpenetration-testing+3
11 month ago
CVE-2026-38526 preview

CVE-2026-38526

GitHubqurclinc/cve-2026-38526

Proof-of-concept exploit for authenticated remote code execution in Krayin CRM v2.2.x via unrestricted file upload, supporting web shell and reverse…

educationexploitationpayload-generation+3
1 month ago
CVE-2012-2982 preview

CVE-2012-2982

GitHub0xtas/cve-2012-2982

Exploits CVE-2012-2982 in Webmin with a Rust PoC that delivers a configurable TCP reverse shell and optional Netcat listener.

educationexploitationlabs-practice+3
33 years ago
Previous12…27Next