Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
CVE-2023-31902 preview

CVE-2023-31902

GitHubxl337x/cve-2023-31902

Pre-auth RCE exploit for Mobile Mouse 3.6.0.4 via TCP (port 9099) and WebSocket (port 35913) with Python scripts for unauthenticated command…

educationexploitationpenetration-testing+3
2 months ago
pwnlift preview

pwnlift

GitHubrasta-mouse/pwnlift

Easy peasy file uploads

data-exfiltrationpenetration-testingremote-access-tool+2
422 months ago
CVE-2026-23744-RCE preview

CVE-2026-23744-RCE

GitHubalisster00/cve-2026-23744-rce

This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object.…

educationexploitationpenetration-testing+3
12 months ago
Cgi-Exploit-Jp-Shell-Upload preview

Cgi-Exploit-Jp-Shell-Upload

GitHubjenderal92/cgi-exploit-jp-shell-upload

Python 2.7

exploitationpenetration-testingremote-access-tool+1
32 months ago
CVE-2015-8522.RCE preview
Archived

CVE-2015-8522.RCE

GitHubdamariion/cve-2015-8522.rce

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

binary-exploitationexploitationexploit-frameworks+8
4 months ago
frida-c2-mcp preview

frida-c2-mcp

GitHubs4dp4nd4/frida-c2-mcp

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

android-securitycommand-and-controldynamic-analysis-sandboxing+8
625 months ago
CVE-2026-31816-rshell preview

CVE-2026-31816-rshell

GitHubimjdl/cve-2026-31816-rshell

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

authenticationexploitationpayload-development+2
5 months ago
CVE-2014-6287 preview

CVE-2014-6287

GitHubjagg3rsec/cve-2014-6287

Exploit implementation for CVE-2014-6287, targeting a remote code execution vulnerability in a web application. Provides a proof-of-concept for…

exploitationpenetration-testingremote-access-tool+2
7 months ago
PunchingBag-for-React2Shell preview

PunchingBag-for-React2Shell

GitHubmachine-farmer/punchingbag-for-react2shell

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

ctfeducationexploitation+6
18 months ago
p0wny-shell preview

p0wny-shell

GitHubflozz/p0wny-shell

Single-file PHP shell

penetration-testingremote-access-toolweb-application-exploitation
2.9k1 year ago
novahot preview
Archived

novahot

GitHubchrisallenlane/novahot

A webshell framework for penetration testers.

command-and-controlexploit-frameworkspayload-generation+3
2991 year ago
RemoteMouse-3.008-RCE preview

RemoteMouse-3.008-RCE

GitHubgoultarde/remotemouse-3.008-rce

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

educationexploitationpayload-generation+3
1 year ago
CVE-2019-12840-NodeJs-Exploit preview

CVE-2019-12840-NodeJs-Exploit

GitHubnote0577/cve-2019-12840-nodejs-exploit

Authenticated Remote Command Execution - Webmin <= 1.910

exploitationremote-access-toolweb-application-exploitation
1 year ago
CVE-2021-38163 preview

CVE-2021-38163

GitHubpurpleteam-ru/cve-2021-38163

CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability

exploitationinformation-gatheringpenetration-testing+3
1 year ago
parquet-rce-poc-CVE-2025-30065 preview

parquet-rce-poc-CVE-2025-30065

GitHubmouadk/parquet-rce-poc-cve-2025-30065

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

educationexploitationpayload-development+3
31 year ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
CVE-2024-32651-changedetection-RCE preview

CVE-2024-32651-changedetection-RCE

GitHubs0ck3t-s3c/cve-2024-32651-changedetection-rce

Server-Side Template Injection Exploit

exploitationpayload-developmentpenetration-testing+3
41 year ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHubpimps/cve-2017-1000486

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

exploitationpayload-generationpenetration-testing+3
952 years ago
Previous12Next