Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
CVE-2026-48907 preview

CVE-2026-48907

GitHubnoname-elv/cve-2026-48907

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

exploitationpayload-developmentpenetration-testing+6
6 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubmatakucing-ofc/cve-2026-49049

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

exploitationpenetration-testingremote-access-tool+4
9 days ago
SmarterMail-CVE-2026-24423 preview

SmarterMail-CVE-2026-24423

GitHubcyberalp0/smartermail-cve-2026-24423

Exploit for CVE-2026-24423 — a critical unauthenticated RCE in SmarterMail's ConnectToHub API. Affects all builds prior to 9511.

exploitationpenetration-testingred-teaming+3
19 days ago
badblood preview

badblood

GitHubjbaines-r7/badblood

SonicWall SMA-100 Unauth RCE Exploit (CVE-2021-20038)

binary-exploitationexploitationpenetration-testing+2
954 years ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubmroplus/cve-2026-41940

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

exploitationpayload-developmentpost-exploitation+2
14 months ago
cve-2022-42475-poc preview

cve-2022-42475-poc

GitHubull0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

exploitationpenetration-testingred-teaming+3
127 days ago
quasibot preview

quasibot

GitHubsmaash/quasibot

complex webshell manager, quasi-http botnet.

command-and-controlexploitationinformation-gathering+6
28411 years ago
CVE-2024-29671-POC preview

CVE-2024-29671-POC

GitHublaskdjlaskdj12/cve-2024-29671-poc

This is POC of CVE-2024-29671

binary-exploitationembedded-systems-securityexploitation+7
11 year ago
CVE-2022-22965-PoC preview

CVE-2022-22965-PoC

GitHubsunnyvale-it/cve-2022-22965-poc

CVE-2022-22965 (Spring4Shell) Proof of Concept

exploitationpayload-generationpenetration-testing+3
73 years ago
React2Shell-CTF preview

React2Shell-CTF

GitHubyz9yt/react2shell-ctf

A CTF challenge based on CVE-2025-55182 Vulnerability

ctfeducationexploitation+3
39 months ago
cve-2019-7609 preview

cve-2019-7609

GitHubcr4ckc4t/cve-2019-7609

Kibana <6.6.0 RCE written in python3

exploitationpenetration-testingremote-access-tool+2
44 years ago
WebSphere-WSIF-gadget preview

WebSphere-WSIF-gadget

GitHubsilentsignal/websphere-wsif-gadget

CVE-2020-4464 / CVE-2020-4450

exploitationpayload-developmentpenetration-testing+3
365 years ago
CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001 preview

CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001

GitHubninjazan420/cve-2025-52691-poc-smartermail-authentication-bypass-exploit-wt-2026-0001

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

authenticationexploitationpenetration-testing+4
8 months ago
CVE-2025-2620-poc preview

CVE-2025-2620-poc

GitHubotsmane-ahmed/cve-2025-2620-poc

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

binary-exploitationembedded-systems-securityexploitation+8
161 year ago
CVE-2025-22457 preview

CVE-2025-22457

GitHubsfewer-r7/cve-2025-22457

PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy…

binary-exploitationexploitationpayload-generation+6
731 year ago
CVE-2024-28397-Js2Py-RCE preview

CVE-2024-28397-Js2Py-RCE

GitHubd3ltaformation/cve-2024-28397-js2py-rce

This repository contains a Proof of Concept (PoC) for CVE-2024-28397, a vulnerability in the js2py library allowing a sandbox escape to achieve…

educationexploitationpayload-development+4
0 years ago
CVE-2022-42889-text4shell preview

CVE-2022-42889-text4shell

GitHubgoultarde/cve-2022-42889-text4shell

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code…

exploitationpayload-generationpenetration-testing+3
12 months ago
CVE-2022-0543 preview

CVE-2022-0543

GitHubk3ystr0k3r/cve-2022-0543

PoC for CVE-2022-0543 – Redis Remote Code Execution (RCE)

educationexploitationpenetration-testing+3
3 months ago
Previous123Next