Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
CVE-2026-57517 preview

CVE-2026-57517

GitHubshinthink/cve-2026-57517

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

exploitationpayload-developmentpenetration-testing+4
1
1 month ago
CVE-2026-2586 preview

CVE-2026-2586

GitHubdeepsecurityresearch/cve-2026-2586
exploitationpayload-generationpenetration-testing+3
22 months ago
CVE-2023-422-Chamilo-LMS-RCE preview

CVE-2023-422-Chamilo-LMS-RCE

GitHubhusenjandev/cve-2023-422-chamilo-lms-rce

Remote Code Execution for Chamilo LMS

exploitationpayload-generationremote-access-tool+2
2 years ago
CVE-2023-31902 preview

CVE-2023-31902

GitHubxl337x/cve-2023-31902
educationexploitationpenetration-testing+3
2 months ago
CocoaPods-RCE_CVE-2024-38366 preview

CocoaPods-RCE_CVE-2024-38366

GitHubreefspek/cocoapods-rce_cve-2024-38366

CocoaPods RCE Vulnerability CVE-2024-38366

command-and-controlexploitationpayload-development+5
12 years ago
graylog-cve-2024-24824-exploit preview

graylog-cve-2024-24824-exploit

GitHubrootkited/graylog-cve-2024-24824-exploit

Proof-of-concept exploit for CVE-2024-24824 demonstrating how an arbitrary class loading primitive can be transformed into remote code execution on…

code-analysiseducationexploitation+3
1 month ago
-CVE-2017-9805- preview

-CVE-2017-9805-

GitHubjongmartinez/-cve-2017-9805-

Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)

exploitationpayload-generationpenetration-testing+3
15 years ago
CVE-2024-0757-Exploit preview

CVE-2024-0757-Exploit

GitHubhunthubspace/cve-2024-0757-exploit

A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)

exploitationpayload-generationpenetration-testing+3
82 years ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubfatkz/cve-2025-24813
code-analysisexploitationpayload-generation+5
11 year ago
OTRS-4.0.1-6.0.1-Remote-Command-Execution preview

OTRS-4.0.1-6.0.1-Remote-Command-Execution

GitHubsmarttfoxx/otrs-4.0.1-6.0.1-remote-command-execution

CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an…

exploitationpenetration-testingremote-access-tool+2
1 year ago
CVE-2025-58434-AND-59528-POC preview

CVE-2025-58434-AND-59528-POC

GitHubkartik2005221/cve-2025-58434-and-59528-poc

Combined PoC for CVE-2025-28434 and CVE-2025-59528

authenticationeducationexploitation+5
174 months ago
CVE-2014-6271 preview

CVE-2014-6271

GitHub0x00-0x00/cve-2014-6271

Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.

command-and-controlexploitationpayload-generation+3
38 years ago
-CVE-2017-9805 preview

-CVE-2017-9805

GitHub0x00-0x00/-cve-2017-9805

Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)

exploitationpayload-generationpenetration-testing+3
155 years ago