Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
679 results
l4srs preview

l4srs

GitHubs-retlaw/l4srs

Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)

command-and-controlexploitationpayload-generation+3
3 years ago
CVE-2020-0910 preview

CVE-2020-0910

GitHubkfmgang/cve-2020-0910

Exploit PoC RCE - Windows Hyper-V Remote Code Execution Reverse Shell

exploitationpayload-generationpenetration-testing+2
6 years ago
Fu3l-F1lt3r preview

Fu3l-F1lt3r

GitHubuwueviee/fu3l-f1lt3r

Rust implementation of CVE-2018-16763 with some extra features.

command-and-controlexploitationpayload-generation+3
5 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubmr-r00t11/cve-2024-23692

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

exploitationpayload-generationpenetration-testing+4
2 years ago
CVE-2023-38646 preview

CVE-2023-38646

GitHubyxl2001/cve-2023-38646

PoC exploit for CVE-2023-38646, a pre-authentication RCE in Metabase. Includes a reverse shell payload generator with base64 encoding fix for…

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubdevadj/cve-2017-12617

Improved version of PikaChu CVE

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubhakankarabacak/cve-2025-24813

Proof of Concept (PoC) script for CVE-2025-24813, vulnerability in Apache Tomcat.

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2024-25180 preview

CVE-2024-25180

GitHubdustblessnotdust/cve-2024-25180

Python exploit script for CVE-2024-25180, a remote code execution vulnerability in pdfmake, delivering a reverse shell via crafted POST requests.

command-and-controlexploitationpayload-generation+3
1 year ago
PyUsernameMapScriptRCE preview

PyUsernameMapScriptRCE

GitHubherculesrd/pyusernamemapscriptrce

CVE-2007-2447 exploit written in python to get reverse shell

exploitationpayload-generationpenetration-testing+2
4 years ago
CVE-2024-4577-Exploit preview

CVE-2024-4577-Exploit

GitHubgill-singh-a/cve-2024-4577-exploit

PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-36401-PoC preview

CVE-2024-36401-PoC

GitHuby1s4s/cve-2024-36401-poc

Proof-of-concept exploit for CVE-2024-36401 enabling remote code execution via HTTP requests with reverse shell payload generation and Base64…

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2023-46604 preview

CVE-2023-46604

GitHubccievoice2009/cve-2023-46604

Exploit for CVE-2023-46604 in Apache ActiveMQ, enabling remote code execution via crafted XML payloads and reverse shell establishment.

exploitationpayload-generationpenetration-testing+3
1 year ago
-CVE-2014-6271-Shellshock-Remote-Command-Injection- preview

-CVE-2014-6271-Shellshock-Remote-Command-Injection-

GitHubfilipstudeny/-cve-2014-6271-shellshock-remote-command-injection-

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

exploitationpayload-generationpenetration-testing+3
4 years ago
weblogic-cve-2018-2628 preview

weblogic-cve-2018-2628

GitHubcscadoge/weblogic-cve-2018-2628

Exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution via ysoserial JRMP listener.

exploitationpayload-developmentpenetration-testing+3
4 years ago
CVE-2021-44228-Apache-Log4j-Rce-main preview

CVE-2021-44228-Apache-Log4j-Rce-main

GitHubravid-checkmarx/cve-2021-44228-apache-log4j-rce-main

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI LDAP/RMI injection, payload compilation, and WAF bypass techniques for testing…

exploitationpayload-generationpenetration-testing+4
4 years ago
CVE-2024-28397-js2py-Sandbox-Escape preview

CVE-2024-28397-js2py-Sandbox-Escape

GitHubcyber-warrior-sec/cve-2024-28397-js2py-sandbox-escape

Proof-of-concept exploit for CVE-2024-28397, a sandbox escape in js2py allowing remote code execution via crafted JavaScript, with a dynamic patch…

code-analysisexploitationpayload-development+3
2 years ago
CVE-2023-30547 preview

CVE-2023-30547

GitHubjunnythemarksman/cve-2023-30547

Python exploit for CVE-2023-30547 vm2 sandbox escape vulnerability. Generates base64-encoded JSON payload to open a reverse shell from vulnerable…

exploitationpayload-generationpenetration-testing+2
2 years ago
Project-Exploiting-CVE-2024-27198-RCE-Vulnerability preview

Project-Exploiting-CVE-2024-27198-RCE-Vulnerability

GitHubartemcyberlab/project-exploiting-cve-2024-27198-rce-vulnerability

In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.

exploitationpayload-developmentpenetration-testing+3
1 year ago
Previous1…333435…38Next