Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
60 results
CVE-2026-39987 preview

CVE-2026-39987

GitHubghxstsec/cve-2026-39987

Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

exploitationpenetration-testingreconnaissance+3
1
23 days ago
ls-poc preview

ls-poc

GitHubtruekas/ls-poc

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

command-and-controlexploitationpayload-development+3
135 months ago
CVE-2026-33017-Exploit preview

CVE-2026-33017-Exploit

GitHuboscar-mine/cve-2026-33017-exploit

Exploit for CVE-2026-33017 — Unauthenticated RCE in Langflow <= 1.8.2 via exec() in flow build endpoint

exploitationpenetration-testingreconnaissance+3
5 months ago
CVE-2025-59287 preview

CVE-2025-59287

GitHubgarvitv14/cve-2025-59287

Automated exploit for CVE-2025-59287, an unauthenticated RCE in WSUS, featuring payload generation, reverse shell listener, and AES encryption with…

command-and-controlexploitationpayload-generation+4
1611 months ago
RCE-CVE-2026-10520-CVE-2026-10523 preview

RCE-CVE-2026-10520-CVE-2026-10523

GitHubimbas007/rce-cve-2026-10520-cve-2026-10523

Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

exploitationpenetration-testingreconnaissance+3
1 month ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k16 days ago
CVE-2025-32432-PoC preview

CVE-2025-32432-PoC

GitHubezramansor/cve-2025-32432-poc

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

adversarial-attackexploitationpayload-generation+3
1 month ago
RingReaper preview

RingReaper

GitHubmatheuzsecurity/ringreaper

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

adversarial-attackcommand-and-controldata-exfiltration+5
3841 year ago
CIMCown preview

CIMCown

GitHubnside-attack-logic/cimcown

PoC toolkit for exploiting Cisco IMC RCE CVE-2026-20200

exploitationpayload-developmentremote-access-tool+2
11 month ago
tap preview

tap

GitHubtrustedsec/tap

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

command-and-controlpenetration-testing-frameworkspersistence-mechanisms+3
5053 years ago
CVE-2021-40539 preview

CVE-2021-40539

GitHublpyydxs/cve-2021-40539

Exploit for CVE-2021-40539: RCE in Zoho ManageEngine ADSelfService Plus. Includes detection script, Fofa search syntax, and webshell deployment for…

exploitationpenetration-testingreconnaissance+3
11 year ago
CVE-2023-25136 preview

CVE-2023-25136

GitHubnhakobyan685/cve-2023-25136

OpenSSH 9.1 vulnerability mass scan and exploit

exploitationnetwork-securitypenetration-testing+3
83 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubverylazytech/cve-2024-23692

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

exploitationpenetration-testingreconnaissance+3
491 year ago
CVE-2022-26809 preview

CVE-2022-26809

GitHubwebsecnl/cve-2022-26809

Remote Code Execution Exploit in the RPC Library

binary-exploitationexploitationpenetration-testing+2
284 years ago
CVE-2022-48565-POC preview

CVE-2022-48565-POC

GitHubeinstein2150/cve-2022-48565-poc

A proof-of-concept for CVE-2022-48565 - python plistlib XML deserialisation attack

binary-exploitationeducationexploitation+3
31 year ago
Log4Shell-CVE-2021-44228-PoC preview

Log4Shell-CVE-2021-44228-PoC

GitHubpierpaolosestito-dev/log4shell-cve-2021-44228-poc

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

command-and-controlexploitationpayload-development+3
13 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubkarmakstylez/cve-2024-6387

Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)

exploitationnetwork-securitypenetration-testing+3
1952 years ago
cve-2026-23744 preview

cve-2026-23744

GitHubrohit-sundar/cve-2026-23744

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated RCE in MCPJam Inspector. Provides reverse shell and command execution via a…

command-and-controleducationexploitation+6
13 months ago
Previous1234Next