Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
CVE-2026-80099 preview

CVE-2026-80099

GitHubwayang1337/cve-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

exploitationinformation-gatheringpassword-attacks+7
1
16 days ago
WBCE-v1.6.3-Authenticated-RCE preview

WBCE-v1.6.3-Authenticated-RCE

GitHubswammers8/wbce-v1.6.3-authenticated-rce

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

exploitationpayload-generationremote-access-tool+1
1 year ago
FreePBX-Reverse-Shell-Module preview

FreePBX-Reverse-Shell-Module

GitHubh3x0v3rl0rd/freepbx-reverse-shell-module

Exploit module for FreePBX delivering a reverse shell payload to achieve remote command execution and persistent shell access, designed for…

exploitationpayload-generationpenetration-testing+3
5 years ago
smb-usermap preview

smb-usermap

GitHubh3x0v3rl0rd/smb-usermap

Python exploit for Samba 3.0.20-3.0.25rc3 'username map script' command injection, providing unauthenticated remote code execution and reverse shell.

exploitationpenetration-testingremote-access-tool
4 years ago
SlackShell preview

SlackShell

GitHubbkup/slackshell

PowerShell to Slack C2

command-and-controlpayload-developmentpenetration-testing+3
1078 years ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
mailenable-cve-2022-36934 preview

mailenable-cve-2022-36934

GitHubtdawg506/mailenable-cve-2022-36934

Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE

exploit-frameworkspayload-developmentpenetration-testing+3
1 year ago
CVE-2015-1578-PoC-Metasploit preview

CVE-2015-1578-PoC-Metasploit

GitHubyaldobaoth/cve-2015-1578-poc-metasploit

This is a proof-of-concept Metasploit module exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation…

binary-exploitationexploitationexploit-frameworks+6
1 year ago
Rejetto-HFS-2.x-RCE-CVE-2024-23692 preview

Rejetto-HFS-2.x-RCE-CVE-2024-23692

GitHubpradeepboo/rejetto-hfs-2.x-rce-cve-2024-23692

Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)

exploitationpayload-generationpenetration-testing+3
12 years ago
pythonprojects-CVE-2018-10933 preview

pythonprojects-CVE-2018-10933

GitHubshifa123/pythonprojects-cve-2018-10933

CVE-2018-10933

command-and-controlexploitationpenetration-testing+2
27 years ago
CVE-2026-42945-Reverse-Shell-POC preview

CVE-2026-42945-Reverse-Shell-POC

GitHubsec-sys/cve-2026-42945-reverse-shell-poc

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

binary-exploitationctfexploitation+6
3 months ago
CVE-2022-31491 preview

CVE-2022-31491

GitHubready2disclose/cve-2022-31491

CVE-2022-31491

command-and-controlexploitationexploit-frameworks+4
6 months ago
Metasploit-Wordpress-Canto-Exploit-RCE preview

Metasploit-Wordpress-Canto-Exploit-RCE

GitHubpuppetma4ster/metasploit-wordpress-canto-exploit-rce

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

exploit-frameworkspayload-developmentpenetration-testing+3
6 months ago
CVE-2021-27877-PoC preview

CVE-2021-27877-PoC

GitHubyashswarup12/cve-2021-27877-poc

A modified version of the Rapid7 Metasploit module for CVE-2021-27877 that supports direct command execution for reliable vulnerability validation.…

educationexploitationexploit-frameworks+3
2 months ago
CVE-2019-3929 preview

CVE-2019-3929

GitHubxfox64x/cve-2019-3929

Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module

command-and-controlexploit-frameworkspenetration-testing+3
56 years ago
CVE-2017-9791 preview

CVE-2017-9791

GitHubxfer0/cve-2017-9791

Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability

exploitationexploit-frameworkspenetration-testing+3
7 years ago
CVE-2016-5640 preview

CVE-2016-5640

GitHubxfox64x/cve-2016-5640

Crestron AirMedia AM-100 RCE (CVE-2016-5640) Metasploit Module

command-and-controlexploitationexploit-frameworks+4
26 years ago
CVE-2012-2982 preview

CVE-2012-2982

GitHubjohnhammond/cve-2012-2982

A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution

exploitationpenetration-testingremote-access-tool+2
425 years ago
Previous12Next