Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
106 results
CVE-2026-48907 preview

CVE-2026-48907

GitHubnoname-elv/cve-2026-48907

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

exploitationpayload-developmentpenetration-testing+6
1
8 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubmatakucing-ofc/cve-2026-49049

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

exploitationpenetration-testingremote-access-tool+4
12 days ago
SmarterMail-CVE-2026-24423 preview

SmarterMail-CVE-2026-24423

GitHubcyberalp0/smartermail-cve-2026-24423

Exploit for CVE-2026-24423 — a critical unauthenticated RCE in SmarterMail's ConnectToHub API. Affects all builds prior to 9511.

exploitationpenetration-testingred-teaming+3
21 days ago
cve-2022-42475-poc preview

cve-2022-42475-poc

GitHubull0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

exploitationpenetration-testingred-teaming+3
129 days ago
grdpwasm preview

grdpwasm

GitHubnakagami/grdpwasm

A web-based RDP client

authenticationencryption-decryption-toolsnetwork-security+3
3201 month ago
filessh preview

filessh

GitHubjayanaxhf/filessh

A fast and convenient TUI file browser for remote servers

network-securityremote-access-toolscripting-automation+1
2312 months ago
cve-2024-38077-madlicense_reproduction preview

cve-2024-38077-madlicense_reproduction

GitHubrazureink/cve-2024-38077-madlicense_reproduction

CVE Reproduction: cve-2024-38077-madlicense_reproduction

binary-exploitationexploitationpenetration-testing+2
2 months ago
RemoteMouse-3.008-RCE preview

RemoteMouse-3.008-RCE

GitHubgoultarde/remotemouse-3.008-rce

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

educationexploitationpayload-generation+3
2 months ago
CVE-2026-44825-Apache-Solr-Scanner preview

CVE-2026-44825-Apache-Solr-Scanner

GitHubgagaltotal/cve-2026-44825-apache-solr-scanner

Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.

command-and-controlexploitationpenetration-testing+3
122 months ago
CVE-2022-42889-text4shell preview

CVE-2022-42889-text4shell

GitHubgoultarde/cve-2022-42889-text4shell

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code…

exploitationpayload-generationpenetration-testing+3
12 months ago
CVE-2026-41089 preview

CVE-2026-41089

GitHubhnytgl/cve-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

binary-exploitationexploitationpenetration-testing+2
133 months ago
CVE-2022-0543 preview

CVE-2022-0543

GitHubk3ystr0k3r/cve-2022-0543

PoC for CVE-2022-0543 – Redis Remote Code Execution (RCE)

educationexploitationpenetration-testing+3
3 months ago
CVE-2025-32433-Exploit-edited preview

CVE-2025-32433-Exploit-edited

GitHubchuzoux/cve-2025-32433-exploit-edited

Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII…

educationexploitationpenetration-testing+3
3 months ago
PaperCut-Authentication_Bypass_and_RCE preview

PaperCut-Authentication_Bypass_and_RCE

GitHubjoaoaugustom/papercut-authentication_bypass_and_rce

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

authenticationeducationexploitation+5
3 months ago
IPFire_2.25_RCE_Authenticated preview

IPFire_2.25_RCE_Authenticated

GitHubjoaoaugustom/ipfire_2.25_rce_authenticated

This exploit is based on CVE-2021-33393 and was built upon the original exploit by Mücahit Saratar, extending it to achieve a reverse shell with root…

exploitationpenetration-testingprivilege-escalation+3
14 months ago
SimpleRemoter preview

SimpleRemoter

GitHubyuanyuanxiang/simpleremoter

A remote control program based on Gh0st: 实现了终端管理、进程管理、窗口管理、远程桌面、文件管理、语音管理、视频管理、服务管理、注册表管理等功能,优化全部代码及整理排版,修复内存泄漏缺陷,程序运行稳定。项目代码仅限于学习和交流用途。

command-and-controleducationlateral-movement+6
1.4k4 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubmroplus/cve-2026-41940

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

exploitationpayload-developmentpost-exploitation+2
14 months ago
CVE-2015-8522.RCE preview
Archived

CVE-2015-8522.RCE

GitHubdamariion/cve-2015-8522.rce

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

binary-exploitationexploitationexploit-frameworks+8
5 months ago
Previous123456Next