Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
cve-2024-56348 preview

cve-2024-56348

GitHubjoshuavanderpoll/cve-2024-56348

Go-based exploit for CVE-2024-56348 targeting JetBrains TeamCity authentication bypass and remote code execution. Provides interactive shell, reverse…

authenticationexploitationpenetration-testing+4
3
6 months ago
CVE-2026-21440-POC-EXP preview

CVE-2026-21440-POC-EXP

GitHubtibbersv6/cve-2026-21440-poc-exp

Proof-of-concept exploit for CVE-2026-21440, enabling file upload and remote command execution on Windows web servers with built-in sensitive path…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubvanboomqi/cve-2024-23692

Python exploit script for CVE-2024-23692, a template injection RCE in Rejetto HFS 2.3m. Supports single and batch URL exploitation with custom…

exploitationpenetration-testingred-teaming+3
122 years ago
CVE-2021-45010 preview

CVE-2021-45010

GitHubsyd-sydneyjr/cve-2021-45010

Authenticated remote code execution exploit for Tiny File Manager 2.4.6, enabling arbitrary command execution on vulnerable web servers.

exploitationpenetration-testingremote-access-tool+2
13 years ago
CVE-2021-22205 preview

CVE-2021-22205

GitHubccordeiro/cve-2021-22205

Python exploit for CVE-2021-22205, a remote command execution in GitLab CE/EE via image file parsing. Supports vulnerability checking, batch…

command-and-controlexploitationpenetration-testing+3
9 months ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubuserb1ank/cve-2021-31630

Exploit for CVE-2021-31630 in OpenPLC, providing a Python script and manual steps to achieve remote code execution via malicious ST file upload and…

command-and-controlexploitationpayload-development+3
11 months ago
CVE-2024-36401 preview

CVE-2024-36401

GitHubniuwoo/cve-2024-36401

POC

command-and-controlexploitationremote-access-tool+2
42 years ago
motioneye-authenticated-RCE preview

motioneye-authenticated-RCE

GitHubpizza-power/motioneye-authenticated-rce

A Python 3 script that uploads a tasks.pickle file that enables RCE in MotionEye. CVE-2021-44255

command-and-controlexploitationpenetration-testing+3
13 years ago
CVE-2022-30525 preview

CVE-2022-30525

GitHubhenry4e36/cve-2022-30525

Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)

command-and-controlexploitationpenetration-testing+3
224 years ago
cve-2025-3248 preview

cve-2025-3248

GitHubbambooqj/cve-2025-3248

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

command-and-controlexploitationpenetration-testing+3
110 months ago
CVE-2022-29464 preview

CVE-2022-29464

GitHubhupe1980/cve-2022-29464

WSO2 Arbitrary File Upload to Remote Command Execution (RCE)

exploitationpayload-generationremote-access-tool+2
33 years ago
Py-RDP-Patcher preview

Py-RDP-Patcher

GitHubsp00kyskelet0n/py-rdp-patcher

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

lateral-movementpenetration-testingremote-access-tool
65 years ago
CVE-2021-44967 preview

CVE-2021-44967

GitHubmonke443/cve-2021-44967

Authenticated (privileged) remote command execution in LimeSurvey Version 5.2.4 via upload and install plugins allows a remote user to upload…

exploitationpayload-generationpenetration-testing+2
11 year ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubpentestical/cve-2021-22204

Shell script exploit for CVE-2021-22204 targeting Exiftool, generating a malicious .djvu file to achieve remote code execution on vulnerable systems.

exploitationpayload-generationremote-access-tool+2
35 years ago
bitbang-cli preview

bitbang-cli

GitHubrichlegrand/bitbang-cli

Establish secure remote access to a machine with interactive shell, file transfer, and web proxy over end-to-end encrypted peer-to-peer WebRTC, using…

network-securitypenetration-testingpost-exploitation+3
3501 day ago
CVE-2024-24590-ClearML-RCE-CMD-POC preview

CVE-2024-24590-ClearML-RCE-CMD-POC

GitHubdiegogarciayala/cve-2024-24590-clearml-rce-cmd-poc

CVE-2024-24590 ClearML RCE&CMD POC

command-and-controlexploitationpayload-generation+3
92 years ago
0-click-RCE-Exploit-for-CVE-2023-51409 preview

0-click-RCE-Exploit-for-CVE-2023-51409

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2023-51409

Unauthenticated 0-click RCE exploit for CVE-2023-51409. Abuses an arbitrary file upload flaw in the AI Engine WordPress plugin to upload a PHP…

exploitationpayload-generationpenetration-testing+4
17 months ago
0-click-RCE-Exploit-for-CVE-2024-50526 preview

0-click-RCE-Exploit-for-CVE-2024-50526

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50526

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

exploitationpayload-generationpenetration-testing+5
37 months ago
Previous123…10Next