Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
157 results
Ashwesker-CVE-2026-21962 preview

Ashwesker-CVE-2026-21962

GitHubboroeurnprach/ashwesker-cve-2026-21962

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

exploitationpayload-developmentpenetration-testing+3
5
7 months ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubsandimfz/cve-2024-23692

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

command-and-controlexploitationpayload-generation+2
17 days ago
POC-CVE-2026-19286 preview

POC-CVE-2026-19286

GitHubrmhowe425/poc-cve-2026-19286

Proof-of-concept exploit for CVE-2026-19286 in Langflow, allowing authenticated remote command execution via crafted HTTP requests.

exploitationpenetration-testingred-teaming+2
10 days ago
CVE-2021-40346 preview

CVE-2021-40346

GitHubalikarimi999/cve-2021-40346

Proof-of-concept exploit for CVE-2021-40346, an integer overflow in HAProxy enabling HTTP request smuggling and potential access control bypass.

exploitationpenetration-testingred-teaming+2
54 years ago
ibm-qradar-ajp_smuggling_CVE-2022-26377_poc preview

ibm-qradar-ajp_smuggling_CVE-2022-26377_poc

GitHubwatchtowrlabs/ibm-qradar-ajp_smuggling_cve-2022-26377_poc

Proof-of-concept exploit for CVE-2022-26377, an AJP smuggling vulnerability that poisons the HTTP response queue of IBM QRadar with a stored redirect.

exploitationpenetration-testingred-teaming+2
52 years ago
sccm_sql_backdoor preview

sccm_sql_backdoor

GitHubsynacktiv/sccm_sql_backdoor

Exploit CVE-2024-43468 and CVE-2025-59213 to implant a controlled backdoor into SCCM Management Point's SQL stored procedure, enabling remote SQL…

command-and-controlexploitationpenetration-testing+3
32 months ago
CVE-2026-41940_exploit preview

CVE-2026-41940_exploit

GitHubgeorge1-adel/cve-2026-41940_exploit

Python exploit for CVE-2026-41940, a critical CRLF injection in cPanel/WHM cpsrvd that bypasses authentication and 2FA, granting root-level access…

authentication-authorizationexploitationpayload-development+4
22 months ago
CVE-2020-14882 preview

CVE-2020-14882

GitHubxfiftyone/cve-2020-14882

Exploit for CVE-2020-14882 targeting Oracle WebLogic Server versions 10 and 12, enabling unauthenticated remote code execution via crafted HTTP…

exploitationpenetration-testingred-teaming+2
55 years ago
cve-2020-14882 preview

cve-2020-14882

GitHubmmioimm/cve-2020-14882

Python exploit script for CVE-2020-14882 targeting Oracle WebLogic Server. Executes remote commands via crafted HTTP requests to unauthenticated…

exploitationpenetration-testingred-teaming+2
35 years ago
CVE-2024-38472 preview

CVE-2024-38472

GitHubabdurahmon3236/cve-2024-38472

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

command-and-controlexploit-frameworkslateral-movement+6
42 years ago
CVE-2025-61882-POC preview

CVE-2025-61882-POC

GitHubmindflarex/cve-2025-61882-poc

Exploit for CVE-2025-61882, a critical pre-auth RCE in Oracle E-Business Suite. Combines SSRF, CRLF injection, HTTP smuggling, and XSLT injection for…

exploitationpayload-generationpenetration-testing+4
3 months ago
CVE-2021-21425-RCE preview

CVE-2021-21425-RCE

GitHubs1lentf00thold/cve-2021-21425-rce

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

exploitationpayload-generationpenetration-testing+3
2 months ago
CVE-2026-33439-PoC preview

CVE-2026-33439-PoC

GitHubibonok/cve-2026-33439-poc

Exploit for OpenAM pre-auth RCE (CVE-2026-33439) using a Java deserialization gadget chain to execute commands and return output directly in the HTTP…

exploitationpayload-developmentpenetration-testing+3
14 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubctzisme/cve-2026-23744

Proof-of-concept exploit for CVE-2026-23744, demonstrating unauthenticated remote code execution in MCPJam Inspector versions up to 1.4.2 via crafted…

exploitationpenetration-testingred-teaming+2
15 months ago
DataEase_Postgresql_JDBC_Bypass-CVE-2025-49002 preview

DataEase_Postgresql_JDBC_Bypass-CVE-2025-49002

GitHubfeng-huang-0520/dataease_postgresql_jdbc_bypass-cve-2025-49002

Proof-of-concept exploit for CVE-2025-49002, a remote code execution vulnerability in DataEase via PostgreSQL JDBC bypass, including a crafted HTTP…

exploitationpenetration-testingred-teaming+2
110 months ago
CVE-2021-25646 preview

CVE-2021-25646

GitHublp008/cve-2021-25646

Exploit for CVE-2021-25646 Apache Druid RCE via crafted HTTP POST request to the sampler endpoint, with embedded payload delivery and Snort detection…

exploitationpayload-generationpenetration-testing+3
25 years ago
CVE-2025-9074-Docker-Desktop-API-Escape-PoC preview

CVE-2025-9074-Docker-Desktop-API-Escape-PoC

GitHubmedaz-sploit/cve-2025-9074-docker-desktop-api-escape-poc

Proof-of-concept exploit for CVE-2025-9074 enabling Docker Desktop API escape via raw HTTP requests. Provides an emulated interactive shell inside a…

cloud-securitycontainer-escapeexploitation+3
3 months ago
cve-2026-33067 preview

cve-2026-33067

GitHublopseg/cve-2026-33067

Nuclei template for detecting CVE-2026-33017, an unauthenticated remote code execution vulnerability in Langflow ≤ 1.8.2. Performs non-destructive…

exploitationpenetration-testingreconnaissance+3
3 months ago
Previous1…345…9Next