Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1405 results
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
5 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubdevianntsec/cve-2025-55182

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

educationexploitationexploit-frameworks+8
15 months ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubdezso-dfield/cve-2023-27350

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

authentication-authorizationcommand-and-controlexploitation+4
9 months ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubmrdottt/cve-2021-22911

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

exploitationpenetration-testingprivilege-escalation+3
3 years ago
Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763- preview

Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-

GitHubartemcyberlab/project-exploiting-a-vulnerability-in-fuel-cms-cve-2018-16763-

The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical…

exploitationpenetration-testingred-teaming+3
1 year ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubsh4den/cve-2022-36804

A loader for bitbucket 2022 rce (cve-2022-36804)

exploitationpenetration-testingremote-access-tool+2
123 months ago
Cgi-Exploit-Jp-Shell-Upload preview

Cgi-Exploit-Jp-Shell-Upload

GitHubjenderal92/cgi-exploit-jp-shell-upload

Python 2.7

exploitationpenetration-testingremote-access-tool+1
34 months ago
CVE-2022-47966 preview

CVE-2022-47966

GitHubsh4den/cve-2022-47966

The manage engine mass loader for CVE-2022-47966

command-and-controlexploitationpenetration-testing+3
73 months ago
n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate preview

n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate

GitHubhackersatyamrastogi/n8n-exploit-cve-2025-68613-n8n-god-mode-ultimate

n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution

command-and-controleducationexploitation+8
59 months ago
Apache-Struts-2-CVE-2017-5638-Exploit- preview

Apache-Struts-2-CVE-2017-5638-Exploit-

GitHubr4v3nbl4ck/apache-struts-2-cve-2017-5638-exploit-

Exploit created by: R4v3nBl4ck end Pacman

command-and-controlexploitationpenetration-testing+3
39 years ago
CVE-2023-6019 preview

CVE-2023-6019

GitHubjoaquinrrr/cve-2023-6019

PoC exploit for CVE-2023-6019 targeting unauthenticated Remote Code Execution in Anyscale Ray Dashboard via the Jobs API. Delivers a reverse shell on…

command-and-controlexploitationpenetration-testing+3
63 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubnoname-elv/cve-2026-48907

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

exploitationpayload-developmentpenetration-testing+6
124 days ago
CVE-2019-19609 preview

CVE-2019-19609

GitHubglowbase/cve-2019-19609

Python exploit script targeting unauthenticated remote code execution in Strapi CMS 3.0.0-beta.17.4 via CVE-2019-18818 and CVE-2019-19609, delivering…

exploitationpenetration-testingremote-access-tool+2
24 years ago
CVE-2019-0708-RCE preview

CVE-2019-0708-RCE

GitHub0x6b7966/cve-2019-0708-rce

CVE-2019-0708 RCE远程代码执行getshell教程

educationexploit-frameworkspenetration-testing+3
17 years ago
CVE-2026-39987_exploit preview

CVE-2026-39987_exploit

GitHubmki9/cve-2026-39987_exploit

Exploit for Marimo pre-auth RCE via WebSocket auth bypass, providing interactive shell access on affected versions.

exploitationpenetration-testingremote-access-tool+2
5 months ago
CVE-2025-55182-React2Shell preview

CVE-2025-55182-React2Shell

GitHubindustri4l-h3ll-xpl0it3rs/cve-2025-55182-react2shell

CVE-2025-55182 Exploit | by infrar3d

educationexploitationpayload-generation+3
4 months ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubosman1337-security/cve-2025-54100

Proof-of-concept for CVE-2025-54100: XSS in PowerShell's Invoke-WebRequest via mshtml.HTMLDocumentClass, enabling remote code execution when curling…

command-and-controlexploitationremote-access-tool+2
239 months ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
22 months ago
Previous1234…79Next