Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
460 results
CVE-2021-44909 preview

CVE-2021-44909

GitHubg1thub3r1st4/cve-2021-44909

orangescrum 1.8.0 - Remote Command Execution RCE (unauthenticated)

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2022-24715 preview

CVE-2022-24715

GitHubcxdxnt/cve-2022-24715

Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10

exploitationpayload-generationpenetration-testing+3
3 years ago
PoC-CVE-2019-12840 preview

PoC-CVE-2019-12840

GitHubpol-ruiz/poc-cve-2019-12840

Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2019-12840 la qual te da un RCE en root

exploitationpayload-generationpenetration-testing+3
2 years ago
PyUsernameMapScriptRCE preview

PyUsernameMapScriptRCE

GitHubherculesrd/pyusernamemapscriptrce

CVE-2007-2447 exploit written in python to get reverse shell

exploitationpayload-generationpenetration-testing+2
4 years ago
vsftpd2.3.4PyExploit preview

vsftpd2.3.4PyExploit

GitHubherculesrd/vsftpd2.3.4pyexploit

An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python

exploitationpayload-generationpenetration-testing+2
5 years ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubktn1990/cve-2024-5084

WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2024-4577-Exploit preview

CVE-2024-4577-Exploit

GitHubgill-singh-a/cve-2024-4577-exploit

PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)

exploitationpayload-generationpenetration-testing+3
1 year ago
WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425 preview

WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425

GitHub0xdtc/wondercms-4.3.2-xss-to-rce-exploits-cve-2023-41425

Exploit scripts for WonderCMS 4.3.2 that chain XSS to RCE by injecting a crafted theme payload and triggering a reverse shell from the admin session.

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2023-4220 preview

CVE-2023-4220

GitHubh4cking4all/cve-2023-4220

Exploit for CVE-2023-4220, a file upload vulnerability in Chamilo LMS <= 1.11.24, enabling remote code execution via webshell upload and reverse…

exploitationpayload-generationremote-access-tool+3
1 year ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubgr4ykt/cve-2011-2523

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers an interactive shell on port 6200 for remote command execution.

exploitationpayload-generationpenetration-testing+3
4 years ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubdevadj/cve-2017-12617

Python exploit for CVE-2017-12617, a critical RCE in Apache Tomcat with HTTP PUT enabled. Scans targets, creates webshells, and provides remote shell…

exploitationpayload-generationpenetration-testing+3
1 year ago
vsftpd-backdoor preview

vsftpd-backdoor

GitHublychi3/vsftpd-backdoor

Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523

command-and-controlexploitationpayload-generation+3
1 year ago
CVE-2023-422-Chamilo-LMS-RCE preview

CVE-2023-422-Chamilo-LMS-RCE

GitHubhusenjandev/cve-2023-422-chamilo-lms-rce

Python exploit script for CVE-2023-422 enabling unauthenticated remote code execution on Chamilo LMS via file upload and reverse shell delivery.

exploitationpayload-generationremote-access-tool+2
2 years ago
-CVE-2014-6271-Shellshock-Remote-Command-Injection- preview

-CVE-2014-6271-Shellshock-Remote-Command-Injection-

GitHubfilipstudeny/-cve-2014-6271-shellshock-remote-command-injection-

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

exploitationpayload-generationpenetration-testing+3
3 years ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubsug4r-wr41th/cve-2011-2523

Proof-of-concept exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523). Executes remote command injection on target host via port 21.

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2025-32433-Remote-Shell preview

CVE-2025-32433-Remote-Shell

GitHubmeloppeitreet/cve-2025-32433-remote-shell

Go-based exploit for CVE-2025-32433 that delivers a remote bash shell by exploiting a pre-authentication SSH protocol flaw in Erlang OTP SSH…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2021-44228-Log4Shell- preview

CVE-2021-44228-Log4Shell-

GitHubkhaidtraivch/cve-2021-44228-log4shell-

Script-based Log4Shell (CVE-2021-44228) exploit toolkit with LDAP server setup, JNDI payload injection via HTTP headers, and reverse shell listener…

command-and-controlexploitationpayload-generation+3
1 year ago
CVE-2023-38646 preview

CVE-2023-38646

GitHubyxl2001/cve-2023-38646

PoC exploit for CVE-2023-38646, a pre-authentication RCE in Metabase. Includes a reverse shell payload generator with base64 encoding fix for…

exploitationpayload-generationpenetration-testing+3
2 years ago
Previous1…23242526Next