Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
683 results
reactshell preview

reactshell

GitHubh4r335hr/reactshell

Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)

exploitationpayload-generationpenetration-testing+2
7 months ago
xwiki-15.10.8-reverse-shell-cve-2025-24893 preview

xwiki-15.10.8-reverse-shell-cve-2025-24893

GitHubbishben/xwiki-15.10.8-reverse-shell-cve-2025-24893

CVE-2025-24893 RCE exploit for XWiki with reverse shell capability

exploitationpayload-generationpenetration-testing+3
1 year ago
cve-2017-12629 preview

cve-2017-12629

GitHubcaptain-woof/cve-2017-12629

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2022-26809-RCE preview

CVE-2022-26809-RCE

GitHublay0us/cve-2022-26809-rce

This repository contains a PoC for remote code execution CVE-2022-26809

exploitationpayload-developmentpenetration-testing+2
4 years ago
Webmin-CVE-2022-0824-Enhanced-Exploit preview

Webmin-CVE-2022-0824-Enhanced-Exploit

GitHubnudttan91/webmin-cve-2022-0824-enhanced-exploit

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

command-and-controlexploitationpayload-generation+6
1 year ago
CVE-2007-2447 preview

CVE-2007-2447

GitHubnika0x38/cve-2007-2447

A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.

command-and-controlexploitationpayload-development+3
1 year ago
CVE-2025-24893 preview

CVE-2025-24893

GitHubandwati/cve-2025-24893

Python exploit for CVE-2025-24893 that executes a reverse shell on vulnerable web applications, with shell upgrade instructions.

command-and-controlexploitationpayload-generation+3
1 year ago
CVE-2024-10914-Exploit preview

CVE-2024-10914-Exploit

GitHubtamirido30/cve-2024-10914-exploit

CVE-2024-10914 Shell Exploit

command-and-controlexploitationpayload-generation+5
1 year ago
Peyara-FileUpload preview

Peyara-FileUpload

GitHubcapture0x/peyara-fileupload

Peyara Remote Mouse Unauthenticated Arbitrary File Upload

exploitationpayload-generationremote-access-tool+1
1 year ago
CVE-2022-1329 preview

CVE-2022-1329

GitHubdexit/cve-2022-1329

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

code-analysisexploitationpayload-development+3
3 years ago
Blackash-CVE-2025-0282 preview

Blackash-CVE-2025-0282

GitHubgmh5225/blackash-cve-2025-0282

Remote code execution exploit for CVE-2025-0282 targeting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. Uploads a web shell to…

exploitationpayload-developmentpenetration-testing+3
1 year ago
Toolshell_CVE-2025-53770 preview

Toolshell_CVE-2025-53770

GitHubgreenforcenetworks/toolshell_cve-2025-53770

Exploit PoC for CVE-2025-53770 enabling webshell upload to SharePoint, ValidationKey extraction, signed ViewState generation, and remote code…

command-and-controlexploitationpayload-generation+4
1 year ago
CVE-2022-35411 preview

CVE-2022-35411

GitHubneo-okami/cve-2022-35411

rpc.py 0.6.0 - Remote Code Execution (RCE)

exploitationpayload-generationpenetration-testing+2
2 years ago
CVE-2024-48061 preview

CVE-2024-48061

GitHubbwithe/cve-2024-48061

CVE-2024-48061 Langflow vulnerable to remote code execution. Poc

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2023-45185 preview

CVE-2023-45185

GitHubafine-com/cve-2023-45185

IBM i Access Client Solutions < 1.1.9.4 - Remote code execution via insecure deserialisation

exploitationpayload-generationpenetration-testing+3
2 years ago
rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287 preview

rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287

GitHubrahisec/rejetto-http-file-server-2.3.x-rce-exploit-cve-2014-6287

This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2020-5903 preview

CVE-2020-5903

GitHubltvthang/cve-2020-5903

Exploit for CVE-2020-5902 targeting F5 BIG-IP RCE via path traversal and JDBC deserialization, enabling command execution, file read/write, and…

exploitationpayload-developmentpenetration-testing+3
6 years ago
CVE-2024-28397-RCE preview

CVE-2024-28397-RCE

GitHubvitaciminipi/cve-2024-28397-rce

CVE-2024-28397 - Remote Code Execution From Vulnerable JS2PY

exploitationpayload-generationremote-access-tool+2
1 year ago
Previous1…313233…38Next