Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
CVE-2026-31816-rshell preview

CVE-2026-31816-rshell

GitHubimjdl/cve-2026-31816-rshell

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

authenticationexploitationpayload-development+2
5 months ago
CVE-2026-21962_Java_GUI_Exploit_Tool preview

CVE-2026-21962_Java_GUI_Exploit_Tool

GitHubnaozibuhao/cve-2026-21962_java_gui_exploit_tool

Java GUI tool for exploiting CVE-2026-21962, an unauthenticated RCE in Oracle WebLogic Proxy Plug-In, enabling multi-target command execution via…

command-and-controlexploitationpenetration-testing+3
25 months ago
CVE-2025-52136 preview

CVE-2025-52136

GitHubf1r3k0/cve-2025-52136

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

command-and-controlexploitationlateral-movement+3
510 months ago
CVE-2025-12399 preview

CVE-2025-12399

GitHubd0n601/cve-2025-12399

Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
10 months ago
cve-2026-4257 preview

cve-2026-4257

GitHubbootstrapbool/cve-2026-4257

Exploit for CVE-2026-4257: Server-Side Template Injection in Contact Form by Supsystic WordPress plugin (≤1.7.36) enabling unauthenticated remote…

exploitationpayload-developmentpenetration-testing+3
4 months ago
android-c-sharp-rat-server preview

android-c-sharp-rat-server

GitHubadvancedhacker101/android-c-sharp-rat-server

This is a plugin for the c# R.A.T server providing extension to android based phone systems

android-securitycommand-and-controldata-exfiltration+3
208 years ago
CVE-2023-3452-PoC preview

CVE-2023-3452-PoC

GitHubleoanggal1/cve-2023-3452-poc

Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)

exploitationpayload-generationpenetration-testing+3
172 years ago
exploit_cve-2023-26326_using_cve-2024-2961 preview

exploit_cve-2023-26326_using_cve-2024-2961

GitHubomarelshopky/exploit_cve-2023-26326_using_cve-2024-2961

Exploit for CVE-2023-26326 in the WordPress BuddyForms plugin, leveraging CVE-2024-2961 for remote code execution. This exploit bypasses PHP 8+…

exploitationpayload-developmentpenetration-testing+3
11 year ago
0-click-RCE-Exploit-for-CVE-2023-51409 preview

0-click-RCE-Exploit-for-CVE-2023-51409

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2023-51409

Unauthenticated 0-click RCE exploit for CVE-2023-51409. Abuses an arbitrary file upload flaw in the AI Engine WordPress plugin to upload a PHP…

exploitationpayload-generationpenetration-testing+4
17 months ago
0-click-RCE-Exploit-for-CVE-2024-50498 preview

0-click-RCE-Exploit-for-CVE-2024-50498

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50498

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

exploitationpayload-generationpenetration-testing+5
17 months ago
0-click-RCE-Exploit-for-CVE-2024-50526 preview

0-click-RCE-Exploit-for-CVE-2024-50526

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50526

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

exploitationpayload-generationpenetration-testing+5
37 months ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubktn1990/cve-2024-5084

WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubraeezrbr/cve-2024-5084

Exploit for CVE-2024-5084: unauthenticated arbitrary file upload in Hash Form WordPress plugin, enabling remote code execution via Python script with…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-39844 preview

CVE-2024-39844

GitHubph1ns/cve-2024-39844

CVE-2024-39844 (ZNC < 1.9.1 modtcl RCE)

exploitationpenetration-testingred-teaming+3
12 years ago
CVE-2024-25600 preview

CVE-2024-25600

GitHubso1icitx/cve-2024-25600

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

exploitationinformation-gatheringpenetration-testing+5
131 year ago
CVE-2024-12252 preview

CVE-2024-12252

GitHubnxploited/cve-2024-12252

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2021-42362 preview

CVE-2021-42362

GitHubsamiba6/cve-2021-42362

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the…

exploitationpayload-developmentremote-access-tool+2
1 year ago
nextploiter preview

nextploiter

GitHubvonuyvicoo/nextploiter

NextJS exploiter for CVE-2025-55182 and more.

exploitationinformation-gatheringpenetration-testing+3
17 months ago
Previous12Next