Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
341 results
METIS preview

METIS

GitHubk3ystr0k3r/metis

Modular Python exploitation framework with a Metasploit-style console, auto-registering Exploit and Auxiliary modules, tri-state checks, and multiple…

command-and-controlctfeducation+9
3
5 days ago
CVE-2026-38526 preview

CVE-2026-38526

GitHubharry178945/cve-2026-38526

Python PoC exploiting CVE-2026-38526 in Krayin CRM <= 2.2.x: authenticated PHP webshell upload via /admin/tinymce/upload leading to remote code…

ctfexploitationpayload-development+5
7 days ago
CVE-2026-38526 preview

CVE-2026-38526

GitHubmrdark-ops/cve-2026-38526

Python PoC exploiting CVE-2026-38526 in Krayin CRM <= 2.2.x: authenticates, uploads a PHP webshell via /admin/tinymce/upload, and executes commands…

ctfexploitationpayload-development+5
7 days ago
CVE-Exploit-Research-Development preview

CVE-Exploit-Research-Development

GitHubfaizanali8232/cve-exploit-research-development

A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with…

command-and-controleducationexploitation+6
6 months ago
CVE-2026-18937 preview

CVE-2026-18937

GitHubabraxas/cve-2026-18937

Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before…

educationexploitationpenetration-testing+4
5 days ago
CVE-2026-77991 preview

CVE-2026-77991

GitHubabraxas/cve-2026-77991

Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

educationexploitationlabs-practice+6
15 days ago
wp2shell-PoC preview

wp2shell-PoC

GitHubarvindear/wp2shell-poc

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

educationexploitationpayload-development+6
5659 days ago
CVE-2026-24061-Telnetd preview

CVE-2026-24061-Telnetd

GitHubish3ng0m4/cve-2026-24061-telnetd

CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass

authenticationeducationexploitation+3
1 month ago
PoC-CVE-2026-33017 preview

PoC-CVE-2026-33017

GitHubmasterwok/poc-cve-2026-33017

Proof-of-concept exploit for CVE-2026-33017 (Langflow <= 1.8.1).

educationexploitationpenetration-testing+3
5 months ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubjorrit-vm/cve-2026-33017

Educational lab demonstrating unauthenticated RCE in Langflow via CVE-2026-33017, with automated VM setup and a PoC exploit for reverse shell.

educationexploitationlabs-practice+6
15 months ago
lab-annie preview

lab-annie

GitHublincolino/lab-annie

Automates exploitation of CVE-2020-13160, a critical remote code execution vulnerability in AnyDesk 5.5.2, enabling penetration testers to validate…

exploitationpenetration-testingred-teaming+2
1 month ago
CVE-2026-65400 preview

CVE-2026-65400

GitHubhorkimhab/cve-2026-65400

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

authenticationeducationexploitation+4
31 month ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
14 months ago
PyHmmm preview

PyHmmm

GitHubcodextf2/pyhmmm

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

command-and-controleducationpayload-development+2
862 years ago
CVE-2026-60004-gitea-0day preview

CVE-2026-60004-gitea-0day

GitHubsachinart/cve-2026-60004-gitea-0day

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

ctfexploitationpenetration-testing+3
2 months ago
OptixGate preview

OptixGate

GitHubdarkcodersc/optixgate

Open-source multi-purpose remote access tool for Microsoft Windows

ctfeducationpost-exploitation+1
2116 months ago
WebShells preview

WebShells

GitHubal1ex/webshells

WebShell studying

command-and-controleducationexploitation+5
135 years ago
Log4Shell-CVE-2021-44228-Demo preview

Log4Shell-CVE-2021-44228-Demo

GitHubra890927/log4shell-cve-2021-44228-demo

Log4Shell CVE-2021-44228 Demo

command-and-controleducationexploitation+5
4 years ago
Previous12…19Next