Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
Langflow-cve-2026-33017-exploit preview

Langflow-cve-2026-33017-exploit

GitHubcerberusmrxi/langflow-cve-2026-33017-exploit

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

command-and-controldata-exfiltrationexploitation+8
1
1 month ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
129 days ago
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

command-and-controlexploitationmemory-forensics+6
113 days ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubkill1234545/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authentication-authorizationexploitationpenetration-testing+5
103 months ago
CVE-2019-11043-Vulnerability preview

CVE-2019-11043-Vulnerability

GitHubmagentabear/cve-2019-11043-vulnerability
educationexploitationlabs-practice+8
8 months ago
Radium preview
Archived

Radium

GitHubmehulj94/radium

Python logger with multiple features.

command-and-controldata-exfiltrationinformation-gathering+7
5245 years ago
TP-Link-ArcherC5-RCE preview

TP-Link-ArcherC5-RCE

GitHubjackdoan/tp-link-archerc5-rce

CVE-2018-19537

command-and-controlembedded-systems-securityexploitation+8
207 years ago
WinRAR-Exploit-Tool---Rust-Edition preview

WinRAR-Exploit-Tool---Rust-Edition

GitHubkitsuneshade/winrar-exploit-tool---rust-edition

A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.

binary-exploitationeducationexploitation+6
811 months ago
react2shell-toolkit preview

react2shell-toolkit

GitHubolezhaku/react2shell-toolkit

Toolkit for CVE-2025-55182, also known as React2Shell.

cloud-securitydatabase-securityexploitation+8
42 months ago
CVE-2025-52691-APT-PoC preview

CVE-2025-52691-APT-PoC

GitHubdeathshotxd/cve-2025-52691-apt-poc

An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation,…

data-exfiltrationeducationexploitation+6
37 months ago
THM---Solar-exploiting-Log-4j preview

THM---Solar-exploiting-Log-4j

GitHubsaru1718/thm---solar-exploiting-log-4j

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

educationexploitationids-ips-evasion+7
5 months ago
CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read preview

CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read

GitHubfazaroot/cve-2025-2539---file-away-wordpress-plugin-arbitrary-file-read

CVE-2025-2539 - File Away WordPress Plugin Arbitrary File Read

ctfeducationexploitation+6
8 months ago
CVE-2022-28672 preview

CVE-2022-28672

GitHubfastmo/cve-2022-28672

CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying

command-and-controlexploitationincident-response+6
3 years ago
taowu-cobalt_strike preview

taowu-cobalt_strike

GitHubpandasec888/taowu-cobalt_strike
command-and-controlexploit-frameworkslateral-movement+7
1.8k9 months ago
phpsploit preview

phpsploit

GitHubnil0x42/phpsploit

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

command-and-controlexploit-frameworkspayload-development+6
2.5k2 years ago
CobaltStrike-Toolset preview

CobaltStrike-Toolset

GitHubqax-a-team/cobaltstrike-toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

command-and-controlexploit-frameworkslateral-movement+8
5923 years ago
ChromeAlone preview

ChromeAlone

GitHubpraetorian-inc/chromealone

A tool to transform Chromium browsers into a C2 Implant

command-and-controlpayload-developmentpersistence-mechanisms+6
6019 months ago
JS-Tap preview

JS-Tap

GitHubhoodoer/js-tap

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

command-and-controldata-exfiltrationinformation-gathering+8
4771 month ago
Previous123Next