Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
86 results
stylesmuggler preview

stylesmuggler

GitHubfortbridge/stylesmuggler

Python PoC reproducing CVE-2026-75650 StyleSmuggler, an unauthenticated Magento RCE via report poisoning and failed-payment rendering, with canary…

exploitationpenetration-testingremote-access-tool+3
8
19 days ago
CVE-2026-34197-PoC preview

CVE-2026-34197-PoC

GitHubnirvanasec/cve-2026-34197-poc

Proof-of-concept exploit for CVE-2026-34197, an RCE in Apache ActiveMQ via Jolokia's addNetworkConnector, with technical notes and reverse shell…

exploitationpenetration-testingred-teaming+3
27 days ago
Project-CVE-2026-33017 preview

Project-CVE-2026-33017

GitHube4zyy/project-cve-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

command-and-controlexploitationpayload-development+6
11 month ago
CVE-2026-23744-Remote-Code-Execution-POC preview

CVE-2026-23744-Remote-Code-Execution-POC

GitHubsuljov/cve-2026-23744-remote-code-execution-poc

Proof-of-concept exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam inspector <=1.4.2, triggered via crafted HTTP requests…

exploitationpenetration-testingremote-access-tool+2
126 months ago
exploit-CVE-2026-23744 preview

exploit-CVE-2026-23744

GitHubluiskrnr/exploit-cve-2026-23744

Exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam Inspector, allowing attackers to execute arbitrary commands via crafted…

exploitationpenetration-testingremote-access-tool+2
45 months ago
CVE-2026-21962_Java_GUI_Exploit_Tool preview

CVE-2026-21962_Java_GUI_Exploit_Tool

GitHubnaozibuhao/cve-2026-21962_java_gui_exploit_tool

Java GUI tool for exploiting CVE-2026-21962, an unauthenticated RCE in Oracle WebLogic Proxy Plug-In, enabling multi-target command execution via…

command-and-controlexploitationpenetration-testing+3
26 months ago
Fenrir preview

Fenrir

GitHubnccgroup/fenrir

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

command-and-controllateral-movementpenetration-testing+3
6711 years ago
Cgi-Exploit-Jp-Shell-Upload preview

Cgi-Exploit-Jp-Shell-Upload

GitHubjenderal92/cgi-exploit-jp-shell-upload

Python 2.7

exploitationpenetration-testingremote-access-tool+1
34 months ago
Peyara-FileUpload preview

Peyara-FileUpload

GitHubcapture0x/peyara-fileupload

Peyara Remote Mouse Unauthenticated Arbitrary File Upload

exploitationpayload-generationremote-access-tool+1
1 year ago
ZeroRAT preview

ZeroRAT

GitHub5alt/zerorat

ZeroRAT是一款windows上的一句话远控

command-and-controldata-exfiltrationexploitation+9
6310 years ago
ReverseHttp preview

ReverseHttp

GitHubd4vinci/reversehttp

Python backdoor that uses http post/get requests to communicate

command-and-controlpayload-developmentpenetration-testing+3
4210 years ago
n00bRAT preview

n00bRAT

GitHubabhishekkr/n00brat

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

command-and-controleducationfingerprint-spoofing+5
1767 years ago
pinky preview

pinky

GitHubdavidtavarez/pinky

pinky - The PHP mini RAT (Remote Administration Tool)

command-and-controlencryption-decryption-toolspayload-generation+6
768 years ago
cve-2021-41773 preview

cve-2021-41773

GitHubmightysai1997/cve-2021-41773

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution (CVE-2021-41773). Includes Docker-based reproduction…

educationexploitationpenetration-testing+3
4 years ago
CVE-2019-0192 preview

CVE-2019-0192

GitHubmpgn/cve-2019-0192

RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl

exploitationpayload-developmentpenetration-testing+3
2087 years ago
Spring4shell-CVE-2022-22965-POC preview

Spring4shell-CVE-2022-22965-POC

GitHubnetcode/spring4shell-cve-2022-22965-poc

Another spring4shell (Spring core RCE) POC

exploitationpayload-generationpenetration-testing+3
34 years ago
CVE-2014-6287 preview

CVE-2014-6287

GitHubnika0x38/cve-2014-6287

A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.

educationexploitationpayload-generation+3
1 year ago
rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287 preview

rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287

GitHubrahisec/rejetto-http-file-server-2.3.x-rce-exploit-cve-2014-6287

This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.

exploitationpayload-generationpenetration-testing+3
1 year ago
Previous12345Next