Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
499 results
cve-2026-87902 preview

cve-2026-87902

GitHubzyphorixofficialmain-lab/cve-2026-87902

Python exploit for CVE-2026-87902, a WordPress Core LFI-to-RCE chain. Fingerprints versions, writes a PHP shell via pearcmd, and provides command…

exploitationinformation-gatheringpayload-development+6
3 days ago
CVE-2026-86218 preview

CVE-2026-86218

GitHubsuper-meuw/cve-2026-86218

Python 3 proof-of-concept exploit for CVE-2026-86218, a pre-auth RCE in N-able N-central via a Struts multipart race condition, with command…

exploitationpayload-developmentpenetration-testing+5
4 days ago
gopacket preview

gopacket

GitHubmandiant/gopacket

A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

command-and-controlexploit-frameworkslateral-movement+7
7071 month ago
CVE-Exploit-Research-Development preview

CVE-Exploit-Research-Development

GitHubfaizanali8232/cve-exploit-research-development

A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with…

command-and-controleducationexploitation+6
6 months ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
11 month ago
CVE-2026-33439-Poc preview

CVE-2026-33439-Poc

GitHubrh33t/cve-2026-33439-poc

PoC for CVE-2026-33439, a pre-auth RCE in OpenAM via unsafe Java deserialization.

exploitationpenetration-testingremote-access-tool+2
6 days ago
CVE-2026-39987_RCE_PoC preview

CVE-2026-39987_RCE_PoC

GitHubmfahdk/cve-2026-39987_rce_poc

Python proof-of-concept for CVE-2026-39987, exploiting an unauthenticated WebSocket terminal endpoint to achieve remote command execution and reverse…

exploitationpenetration-testingremote-access-tool+3
7 days ago
CVE-2026-23744-POC preview

CVE-2026-23744-POC

GitHub0xsoulaimane/cve-2026-23744-poc

CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.

exploitationpayload-generationpenetration-testing+4
3 months ago
CVE-2026-33439-PoC preview

CVE-2026-33439-PoC

GitHubjonaschen0103/cve-2026-33439-poc

Python PoC exploiting CVE-2026-33439, a pre-auth RCE in OpenAM via Java deserialization of the jato.clientSession parameter, with interactive and…

exploitationpayload-generationpenetration-testing+4
7 days ago
MS09-050 preview

MS09-050

GitHubbytejmp/ms09-050

Python exploit for MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow, with vulnerability scanner, arch auto-detection, and x86/x64 reverse…

exploitationinformation-gatheringnetwork-security+7
9 days ago
CVE-2026-33439-Python-PoC preview

CVE-2026-33439-Python-PoC

GitHubinfernosalex/cve-2026-33439-python-poc

Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization

exploitationpenetration-testingremote-access-tool+2
414 days ago
CVE-2024-2044 preview

CVE-2024-2044

GitHubhanzzly/cve-2024-2044

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…

exploitationpayload-developmentpenetration-testing+5
114 days ago
stylesmuggler preview

stylesmuggler

GitHubfortbridge/stylesmuggler

Python PoC reproducing CVE-2026-75650 StyleSmuggler, an unauthenticated Magento RCE via report poisoning and failed-payment rendering, with canary…

exploitationpenetration-testingremote-access-tool+3
815 days ago
CVE-2026-80099 preview

CVE-2026-80099

GitHubwayang1337/cve-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

exploitationinformation-gatheringpassword-attacks+7
115 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubmatakucing-ofc/cve-2026-49049

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

exploitationpenetration-testingremote-access-tool+4
15 days ago
TornadoRevC2 preview

TornadoRevC2

GitHubkamalx06/tornadorevc2

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

command-and-controlinformation-gatheringlateral-movement+8
332 days ago
CVE-2026-34197-PoC preview

CVE-2026-34197-PoC

GitHubnirvanasec/cve-2026-34197-poc

Proof-of-concept exploit for CVE-2026-34197, an RCE in Apache ActiveMQ via Jolokia's addNetworkConnector, with technical notes and reverse shell…

exploitationpenetration-testingred-teaming+3
23 days ago
cve-2025-55182 preview

cve-2025-55182

GitHubchrisbarack/cve-2025-55182

Technical penetration testing writeup demonstrating exploitation of CVE-2025-55182 in Next.js, credential harvesting from SQLite, and privilege…

exploitationpenetration-testingprivilege-escalation+4
25 days ago
Previous12…28Next