Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
CVE-2022-35914-RCE preview

CVE-2022-35914-RCE

GitHubcyb3rk0ala/cve-2022-35914-rce

PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.

exploitationpenetration-testingremote-access-tool+1
13 days ago
WP2Shell preview

WP2Shell

GitHubg0d150ne/wp2shell

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

exploitationexploit-frameworkspayload-development+7
14 days ago
TongDa-RCE preview

TongDa-RCE

GitHubal1ex/tongda-rce

Python-based exploit for Tongda OA remote code execution by chaining file inclusion and upload vulnerabilities to obtain a reverse shell.

exploitationpenetration-testingremote-access-tool+1
96 years ago
Redis-RCE preview

Redis-RCE

GitHubal1ex/redis-rce

Exploit tool for Redis 4.x/5.x that achieves remote code execution by loading a custom RedisModule (exp.so) through a rogue server, enabling…

database-securityexploitationpenetration-testing+3
46 years ago
p0wny-shell preview

p0wny-shell

GitHubflozz/p0wny-shell

Single-file PHP web shell for remote command execution with file upload/download and command history, designed for penetration testing of PHP…

penetration-testingremote-access-toolweb-application-exploitation
2.9k1 year ago
oracleShell preview

oracleShell

GitHubjas502n/oracleshell

Java-based Oracle database exploitation tool for command execution, file management, and reverse shell via PL/SQL functions.

database-securityexploitationpayload-development+2
5855 years ago
Cgi-Exploit-Jp-Shell-Upload preview

Cgi-Exploit-Jp-Shell-Upload

GitHubjenderal92/cgi-exploit-jp-shell-upload

Exploitation tool for CGI shell upload vulnerabilities. Uploads a web shell to vulnerable CGI endpoints, granting remote command execution on the…

exploitationpenetration-testingremote-access-tool+1
32 months ago
CVE-2026-61511-PoC-Exploit preview

CVE-2026-61511-PoC-Exploit

GitHubtc4dy/cve-2026-61511-poc-exploit

Exploit toolkit for CVE-2026-61511 targeting vBulletin pre-auth RCE, featuring multi-endpoint exploitation, WAF bypass via PHPFuck, and…

database-securityexploitationnetwork-mapping+7
518 days ago
CVE-2019-12840-NodeJs-Exploit preview

CVE-2019-12840-NodeJs-Exploit

GitHubnote0577/cve-2019-12840-nodejs-exploit

Node.js exploit script that achieves authenticated remote command execution on vulnerable Webmin instances (CVE-2019-12840) for penetration testing.

exploitationremote-access-toolweb-application-exploitation
1 year ago
CVE-2025-8714-POC preview

CVE-2025-8714-POC

GitHuborderby99/cve-2025-8714-poc

Proof-of-concept for CVE-2025-8714, demonstrating remote code execution in PostgreSQL via malicious pg_dump flat-format dumps, with automated reverse…

database-securityeducationexploitation+3
211 months ago
CVE-2019-9193 preview

CVE-2019-9193

GitHubpaulotrindadec/cve-2019-9193

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

database-securityexploitationpenetration-testing+2
13 years ago
CVE-2026-57517 preview

CVE-2026-57517

GitHubshinthink/cve-2026-57517

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

exploitationpayload-developmentpenetration-testing+4
11 month ago
cve-2021-29442-Nacos-Derby-rce-exp preview

cve-2021-29442-Nacos-Derby-rce-exp

GitHubnanaao/cve-2021-29442-nacos-derby-rce-exp

Exploit script for CVE-2021-29442 targeting Nacos Derby RCE via SQL injection. Automates unauthorized access and remote command execution on…

command-and-controldatabase-securityexploitation+3
1 year ago
cve-2019-9193 preview

cve-2019-9193

GitHubwkjung0624/cve-2019-9193

Proof-of-concept exploit for CVE-2019-9193, enabling remote code execution in PostgreSQL via the COPY TO/FROM PROGRAM feature, targeting superuser…

database-securityexploitationpenetration-testing+3
35 years ago
CVE-2019-16278 preview

CVE-2019-16278

GitHubjas502n/cve-2019-16278

Directory transversal to remote code execution

exploitationremote-access-toolvulnerability-analysis+1
706 years ago
CVE-2019-9193 preview

CVE-2019-9193

GitHubb4kesn4ke/cve-2019-9193

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

database-securityexploitationpayload-development+3
214 years ago
CVE-2022-24706 preview

CVE-2022-24706

GitHubjunghyeonkum/cve-2022-24706

Proof-of-concept exploit for CVE-2022-24706 targeting Apache CouchDB 3.2.1 and below. Demonstrates remote command execution via Erlang Distribution…

database-securityeducationexploitation+3
1 month ago
CVE-2023-39593 preview

CVE-2023-39593

GitHubant1sec-ops/cve-2023-39593

Step-by-step guide to exploit MariaDB UDF vulnerability for authenticated code execution, including DLL upload, function creation, and reverse shell…

command-and-controldatabase-securityeducation+6
21 year ago
Previous12Next