Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
57 results
cve-2024-24919 preview

cve-2024-24919

GitHubsatchhacker/cve-2024-24919

Shell script that tests for CVE-2024-24919 by sending curl requests to specified IPs/domains, intended for educational vulnerability assessment.

educationexploitationreconnaissance+2
2 years ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubgraphite-org/cve-2024-4577

Shell script to scan domains for CVE-2024-4577 PHP remote code execution vulnerability via crafted POST requests, exporting vulnerable targets for…

exploitationpenetration-testingreconnaissance+2
2 years ago
CVE-2024-3094 preview

CVE-2024-3094

GitHubashwani95/cve-2024-3094

Shell script to detect if the ssh binary is likely vulnerable to CVE-2024-3094, without requiring hexdump.

exploitationinformation-gatheringreconnaissance+2
2 years ago
CVE-2020-13942 preview

CVE-2020-13942

GitHubblackmarketer/cve-2020-13942

Shell script to exploit CVE-2020-13942 on web targets, with pre-scanning via httpx or httprob and batch processing from a target list.

exploitationpenetration-testingreconnaissance+2
35 years ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Weaponized web shell

penetration-testingpost-exploitationprivilege-escalation+4
3.5k11 months ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
chomtesh preview

chomtesh

GitHubmr-rizwan-syed/chomtesh

CHOMTE.SH is a powerful shell script designed to automate reconnaissance tasks during penetration testing. It utilizes various Go-based tools to…

dns-subdomain-enumerationinformation-gatheringosint+7
1366 months ago
CVE-2023-35078 preview

CVE-2023-35078

GitHublager1/cve-2023-35078

Shell script to check Ivanti EPMM (MobileIron Core) instances for CVE-2023-35078 remote unauthenticated API access vulnerability, with Shodan dorks…

exploitationinformation-gatheringreconnaissance+2
53 years ago
React2Shell-PoC-CVE-2025-55182 preview

React2Shell-PoC-CVE-2025-55182

GitHubeagle-nett/react2shell-poc-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Includes a scanner for vulnerable hosts and a…

educationexploitationlabs-practice+4
5 months ago
cve-2022-1388-1veresk preview

cve-2022-1388-1veresk

GitHubiveresk/cve-2022-1388-1veresk

Simple shell script for the exploit

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubp3wc0/cve-2024-24919

Shell script to exploit CVE-2024-24919, enabling path traversal file retrieval from Check Point Security Gateways. Supports single IP and batch…

exploitationpenetration-testingreconnaissance+2
2 years ago
CVE-2020-13942 preview

CVE-2020-13942

GitHubprodrious/cve-2020-13942

Shell script to exploit CVE-2020-13942, a remote code execution vulnerability in Apache Unomi, with pre-scanning via httpx or httprob.

exploitationpenetration-testingreconnaissance+2
5 years ago
CVE-2023-43208-MIRTHCONNECT preview

CVE-2023-43208-MIRTHCONNECT

GitHubj4f9s5d2q7/cve-2023-43208-mirthconnect

Shell script to identify and exploit CVE-2023-43208, an unauthenticated remote code execution vulnerability in NextGen Mirth Connect before version…

exploitationinformation-gatheringreconnaissance+2
2 years ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubphirojshah/cve-2024-4577

Proof-of-concept exploit for PHP CGI argument injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers with scanning…

educationexploitationpayload-generation+5
22 years ago
quiver preview

quiver

GitHubstevemcilwain/quiver

Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.

exploitationinformation-gatheringpenetration-testing+4
2166 years ago
autopwn preview

autopwn

GitHubnccgroup/autopwn

Specify targets and run sets of tools against them

penetration-testingpenetration-testing-frameworksreconnaissance+2
3887 years ago
Port-enumeration preview

Port-enumeration

GitHubivanglinkin/port-enumeration

Have you ever faced with the lack of possibility of using NMap? For instance if you have reverse shell as an unprivileged user and there are no…

network-securitypenetration-testingport-scanning+1
333 years ago
CVE-2026-14762-PoC-Exploit preview

CVE-2026-14762-PoC-Exploit

GitHubtc4dy/cve-2026-14762-poc-exploit

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

command-and-controldatabase-securityexploitation+7
22 months ago
Previous1234Next