Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
Embedded-PDF preview

Embedded-PDF

GitHubjasmoon99/embedded-pdf

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

command-and-controleducationexploitation+6
71
5 years ago
PoC-CVE-2025-62222 preview

PoC-CVE-2025-62222

GitHubsadisticnight/poc-cve-2025-62222

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

command-and-controleducationexploit-frameworks+7
16 months ago
maalik preview
Archived

maalik

GitHubquantumcore/maalik

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

command-and-controlexploitationlateral-movement+6
935 years ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubmrr0b0t19/cve-2025-55182-shellinteractive

Interactive RCE exploit for CVE-2025-55182 targeting Next.js/React Server Components deserialization vulnerability. Features automatic detection,…

command-and-controlexploitationpayload-generation+4
219 months ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubalyaapm/cve-2025-55182-shellinteractive

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

command-and-controlexploitationpayload-generation+4
6 days ago
CVE-2021-42362 preview

CVE-2021-42362

GitHubsamiba6/cve-2021-42362

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the…

exploitationpayload-developmentremote-access-tool+2
1 year ago
CVE-2025-27636-RCE-in-Apache-Camel preview

CVE-2025-27636-RCE-in-Apache-Camel

GitHubac8999/cve-2025-27636-rce-in-apache-camel

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

exploitationpayload-generationpenetration-testing+3
5 days ago
CVE-2020-9484-exploit preview

CVE-2020-9484-exploit

GitHubanjai94/cve-2020-9484-exploit

Exploit script for Apache Tomcat RCE via deserialization (CVE-2020-9484), leveraging ysoserial payloads to achieve remote code execution.

exploitationpayload-developmentremote-access-tool+2
66 years ago
hfs2 preview

hfs2

GitHubwgetnz/hfs2

CVE-2024-23692 | HFS 2.3m/2.4-RC07 RCE vulnerability fix

exploitationpenetration-testingremote-access-tool+2
6 months ago
CVE-2019-17662 preview

CVE-2019-17662

GitHubtamagaft/cve-2019-17662

Golang implementation of CVE-2019-17662 TinyVNC Arbitrary File Read leading to Authentication Bypass Exploit

authenticationbinary-exploitationexploitation+2
4 years ago
openssh-portable preview

openssh-portable

GitHubopenssh/openssh-portable

Portable OpenSSH

authenticationcryptographynetwork-security+1
4.0k11 days ago
vm-filesystem preview

vm-filesystem

GitHubinfinitycurvelabs/vm-filesystem

Filesystem interaction via firebeam virtual machine execution

command-and-controlpenetration-testingpost-exploitation+3
585 months ago
TerraMaster-TOS-CVE-2020-15568 preview

TerraMaster-TOS-CVE-2020-15568

GitHubdivinepwner/terramaster-tos-cve-2020-15568

Repository for CVE-2020-15568 Metasploit module

command-and-controlexploit-frameworkspenetration-testing+3
33 years ago
novahot preview
Archived

novahot

GitHubchrisallenlane/novahot

A webshell framework for penetration testers.

command-and-controlexploit-frameworkspayload-generation+3
2991 year ago
rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287 preview

rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287

GitHubrahisec/rejetto-http-file-server-2.3.x-rce-exploit-cve-2014-6287

This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-22514-Remote-Code-Execution preview

CVE-2024-22514-Remote-Code-Execution

GitHuborange-418/cve-2024-22514-remote-code-execution

Proof-of-concept exploit for CVE-2024-22514 enabling remote code execution in iSpyConnect Agent DVR 5.1.6.0 via malicious objects.xml file…

exploitationpenetration-testingremote-access-tool+2
2 years ago
fileless-xec preview

fileless-xec

GitHubariary/fileless-xec

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

command-and-controlexploitationids-ips-evasion+7
2102 years ago
langflow-rce-exploit preview

langflow-rce-exploit

GitHub0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

command-and-controlexploitationpayload-development+8
71 year ago
Previous1234…10Next