Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
eximrce-CVE-2019-10149 preview

eximrce-CVE-2019-10149

GitHubcowbe0x004/eximrce-cve-2019-10149

simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.

exploitationpenetration-testingremote-access-tool+2
14
7 years ago
CVE-2025-24813-PoC-exploit preview

CVE-2025-24813-PoC-exploit

GitHubgunyakit/cve-2025-24813-poc-exploit

Proof-of-concept exploit for Apache Tomcat deserialization RCE (CVE-2025-24813). Uploads a crafted session file via PUT request and triggers…

exploitationpayload-developmentpenetration-testing+3
9 months ago
CVE-2026-1555 preview

CVE-2026-1555

GitHubnxploited/cve-2026-1555

WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload

exploitationpenetration-testingremote-access-tool+2
95 months ago
CVE-2025-69212-PoC preview

CVE-2025-69212-PoC

GitHubbridgeralderson/cve-2025-69212-poc

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

command-and-controlexploitationpayload-development+5
42 months ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
2101 month ago
filessh preview

filessh

GitHubjayanaxhf/filessh

A fast and convenient TUI file browser for remote servers

network-securityremote-access-toolscripting-automation+1
2301 month ago
CVE-2026-54424 preview

CVE-2026-54424

GitHubtomadimitrie/cve-2026-54424

Exploiting Parsec for Windows to gain SYSTEM privileges

binary-exploitationcommand-and-controlexploitation+5
2 months ago
CVE-2022-22029-NFS-Server- preview

CVE-2022-22029-NFS-Server-

GitHubmchoudhary15/cve-2022-22029-nfs-server-

Proof-of-concept exploit for CVE-2022-22029, a Windows NFS remote code execution vulnerability. Includes PowerShell commands to disable NFSV3 as a…

exploitationnetwork-securitypenetration-testing+2
14 years ago
Webmin-CVE-2022-0824-Enhanced-Exploit preview

Webmin-CVE-2022-0824-Enhanced-Exploit

GitHubnudttan91/webmin-cve-2022-0824-enhanced-exploit

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

command-and-controlexploitationpayload-generation+6
1 year ago
cve-2025-0364 preview

cve-2025-0364

GitHubvulncheck-oss/cve-2025-0364

CVE-2025-0364: BigAnt Server RCE Exploit

authenticationexploitationpenetration-testing+3
71 year ago
SecurityNotFound preview

SecurityNotFound

GitHubarchive-puma/securitynotfound

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

payload-generationremote-access-toolweb-security
914 years ago
sshelf preview

sshelf

GitHubmax-rh/sshelf

Fast terminal UI for your SSH hosts: fuzzy-search and connect in two keystrokes, dual-pane SFTP file transfer, and background port forwarding. Keeps…

authenticationgeneral-purpose-utilitiesnetwork-security+2
7118h 12m ago
CVE-2026-15409-15410-Framework preview

CVE-2026-15409-15410-Framework

GitHubtc4dy/cve-2026-15409-15410-framework

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

command-and-controleducationexploitation+7
510 days ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
11 month ago
phone-deck preview

phone-deck

GitHubsmit-shah-gg/phone-deck

Self-hosted control deck and remote desktop for Linux workstations over Tailscale, featuring WebRTC streaming, voice control with local LLM, scene…

remote-access-tool
222 months ago
CVE-2021-26828_ScadaBR_RCE preview

CVE-2021-26828_ScadaBR_RCE

GitHubhev0x/cve-2021-26828_scadabr_rce

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

exploitationpenetration-testingremote-access-tool+3
95 years ago
CVE-2022-1329 preview

CVE-2022-1329

GitHubdexit/cve-2022-1329

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

code-analysisexploitationpayload-development+3
3 years ago
PoC-for-CVE-2020-28948-CVE-2020-28949 preview

PoC-for-CVE-2020-28948-CVE-2020-28949

GitHubjinhao-l/poc-for-cve-2020-28948-cve-2020-28949

Proof-of-concept exploit for CVE-2020-28948 and CVE-2020-28949 targeting PHAR deserialization and inclusion vulnerabilities in Archive_Tar, enabling…

exploitationpayload-developmentpenetration-testing+3
3 years ago
Previous1…345…10Next