Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
PyUsernameMapScriptRCE preview

PyUsernameMapScriptRCE

GitHubherculesrd/pyusernamemapscriptrce

CVE-2007-2447 exploit written in python to get reverse shell

exploitationpayload-generationpenetration-testing+2
4 years ago
CVE-2024-36401-PoC preview

CVE-2024-36401-PoC

GitHuby1s4s/cve-2024-36401-poc

Proof-of-concept exploit for CVE-2024-36401 enabling remote code execution via HTTP requests with reverse shell payload generation and Base64…

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2023-46604 preview

CVE-2023-46604

GitHubccievoice2009/cve-2023-46604

Exploit for CVE-2023-46604 in Apache ActiveMQ, enabling remote code execution via crafted XML payloads and reverse shell establishment.

exploitationpayload-generationpenetration-testing+3
1 year ago
-CVE-2014-6271-Shellshock-Remote-Command-Injection- preview

-CVE-2014-6271-Shellshock-Remote-Command-Injection-

GitHubfilipstudeny/-cve-2014-6271-shellshock-remote-command-injection-

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

exploitationpayload-generationpenetration-testing+3
4 years ago
CVE-2020-8165 preview

CVE-2020-8165

GitHubassassinukg/cve-2020-8165

Python exploit shell for CVE-2020-8165, providing a reverse shell payload for remote code execution on vulnerable Rails applications.

exploitationpayload-generationpenetration-testing+2
5 years ago
cve-2023-38646-metabase-ReverseShell preview

cve-2023-38646-metabase-ReverseShell

GitHubany3ite/cve-2023-38646-metabase-reverseshell

Go-based exploit for CVE-2023-38646 in Metabase, enabling remote code execution and reverse shell connection to an attacker-controlled host.

exploitationpayload-generationpenetration-testing+3
3 years ago
CVE-2024-50498 preview

CVE-2024-50498

GitHubnxploited/cve-2024-50498

Exploit script for CVE-2024-50498 code injection in WordPress WP Query Console that checks vulnerability and delivers a reverse shell.

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2023-30547 preview

CVE-2023-30547

GitHubjunnythemarksman/cve-2023-30547

Python exploit for CVE-2023-30547 vm2 sandbox escape vulnerability. Generates base64-encoded JSON payload to open a reverse shell from vulnerable…

exploitationpayload-generationpenetration-testing+2
2 years ago
CVE-2020-24186 preview

CVE-2020-24186

GitHubgazettel/cve-2020-24186

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…

exploitationpayload-generationpenetration-testing+4
1 year ago
CVE-2023-46604 preview

CVE-2023-46604

GitHubcuanh2333/cve-2023-46604

PoC exploit for CVE-2023-46604 targeting Apache ActiveMQ, delivering a reverse shell via crafted XML payload over HTTP.

exploitationpayload-generationpenetration-testing+3
1 year ago
FreePBX-Reverse-Shell-Module preview

FreePBX-Reverse-Shell-Module

GitHubh3x0v3rl0rd/freepbx-reverse-shell-module

Exploit module for FreePBX delivering a reverse shell payload to achieve remote command execution and persistent shell access, designed for…

exploitationpayload-generationpenetration-testing+3
5 years ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubraeezrbr/cve-2024-5084

Exploit for CVE-2024-5084: unauthenticated arbitrary file upload in Hash Form WordPress plugin, enabling remote code execution via Python script with…

exploitationpayload-generationpenetration-testing+3
1 year ago
WBCE-v1.6.3-Authenticated-RCE preview

WBCE-v1.6.3-Authenticated-RCE

GitHubswammers8/wbce-v1.6.3-authenticated-rce

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

exploitationpayload-generationremote-access-tool+1
1 year ago
CVE-2023-26035 preview
Archived

CVE-2023-26035

GitHubheapbytes/cve-2023-26035

Proof-of-concept exploit for CVE-2023-26035, a remote code execution vulnerability in ZoneMinder versions prior to 1.36.33 and 1.37.33. Supports…

exploitationpayload-generationpenetration-testing+3
72 years ago
webmin_cve-2019-12840_poc preview

webmin_cve-2019-12840_poc

GitHubkre80r/webmin_cve-2019-12840_poc

A standalone POC for CVE-2019-12840

exploitationpayload-generationpenetration-testing+3
86 years ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubcilectiy/cve-2025-49844

CVE-2025-49844

exploitationpayload-generationpenetration-testing+2
16 months ago
CVE-2025-14700-poc preview

CVE-2025-14700-poc

GitHubnosiume/cve-2025-14700-poc

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1

exploitationpayload-generationpenetration-testing+3
19 months ago
CVE-2022-24637 preview

CVE-2022-24637

GitHub0xryuk/cve-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

exploitationpayload-generationremote-access-tool+2
13 years ago
Previous1234Next