Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
117 results
Craft-CMS-Exploit preview

Craft-CMS-Exploit

GitHubdiegaccio/craft-cms-exploit

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

exploitationpenetration-testingred-teaming+3
52 years ago
CVE-2024-3273 preview

CVE-2024-3273

GitHubap0dexme0/cve-2024-3273

D-Link NAS Command Execution Exploit

command-and-controlexploitationiot-security+3
52 years ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubkyukazamiqq/cve-2026-24061

Multi-threaded Telnet vulnerability scanner that exploits CVE-2026-24061 via environment variable injection, verifies root access, and provides an…

educationexploitationnetwork-security+3
2 months ago
Webmin_CVE-2019-15107 preview

Webmin_CVE-2019-15107

GitHubsquid22/webmin_cve-2019-15107

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920

exploitationpenetration-testingremote-access-tool+2
35 years ago
CVE-2026-6279.py preview

CVE-2026-6279.py

GitHub87achrafg-stack/cve-2026-6279.py

CVE-2026-6279

command-and-controlexploitationpayload-development+5
12 months ago
CVE-2023-45878 preview

CVE-2023-45878

GitHubcan0i0ever0enter/cve-2023-45878

Python exploit for CVE-2023-45878, an unauthenticated arbitrary file upload in Gibbon CMS, enabling RCE via webshell upload and interactive shell…

exploitationpayload-generationpenetration-testing+3
31 year ago
OpenSTAManager_RCE_Exploit-CVE-2026-38751- preview

OpenSTAManager_RCE_Exploit-CVE-2026-38751-

GitHubhackthem/openstamanager_rce_exploit-cve-2026-38751-

OpenSTAManager RCE Exploit (CVE-2026-38751)

exploitationpayload-generationpenetration-testing+4
11 month ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubbyteforgefr/cve-2011-2523

VsFTPd 2.3.4 Backdoor Command Execution

command-and-controlexploitationpayload-generation+3
13 months ago
CVE-2023-0830 preview

CVE-2023-0830

GitHubxbz0n/cve-2023-0830

Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.

command-and-controlexploitationpayload-generation+3
11 year ago
SQLPad-6.10.0-Exploit-CVE-2022-0944 preview

SQLPad-6.10.0-Exploit-CVE-2022-0944

GitHub0xdtc/sqlpad-6.10.0-exploit-cve-2022-0944

Refurbish

educationexploitationpenetration-testing+3
1 year ago
CVE-2020-14882 preview

CVE-2020-14882

GitHubaleksazatezalo/cve-2020-14882

Exploits Oracle WebLogic Server RCE (CVE-2020-14882) to execute commands on vulnerable targets, capturing output via HTTP listener.

command-and-controlexploitationremote-access-tool+2
1 year ago
CVE-2020-14882 preview

CVE-2020-14882

GitHubroot-shells/cve-2020-14882

CVE-2020-14882 rewritten in PowerShell

exploitationpenetration-testingremote-access-tool+2
1 year ago
Exploit-CVE-2011-2523 preview

Exploit-CVE-2011-2523

GitHubshubham-2k1/exploit-cve-2011-2523

Python exploit for VSFTP 2.3.4 backdoor (CVE-2011-2523) that triggers the backdoor and provides shell access on port 6200.

binary-exploitationeducationexploitation+3
2 years ago
LongBow preview

LongBow

GitHubstanleyjobsonau/longbow

CVE-2023-31756 Proof of Concept - Remote Code Execution for Archer V1/V2 Routers

exploitationpenetration-testingremote-access-tool+2
22 years ago
CVE-2024-21546 preview

CVE-2024-21546

GitHubajdumanhug/cve-2024-21546

This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions…

exploitationpayload-generationpenetration-testing+3
51 year ago
metabase-pre-auth-rce-poc preview

metabase-pre-auth-rce-poc

GitHubm3m0o/metabase-pre-auth-rce-poc

This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.

exploitationpenetration-testingred-teaming+3
22 years ago
sticky_keys_hunter preview

sticky_keys_hunter

GitHubztgrace/sticky_keys_hunter

A script to test an RDP host for sticky keys and utilman backdoor.

penetration-testingpost-exploitationremote-access-tool+1
2639 years ago
React2Shell-CVE-2025-55182-PoC-Reverse-Shell preview

React2Shell-CVE-2025-55182-PoC-Reverse-Shell

GitHubihhgimhana/react2shell-cve-2025-55182-poc-reverse-shell

This is an easy to use PoC script to exploit React2Shell-CVE-2025-55182 Nextjs vulnerability. This will help to gain a reverse shell.

educationexploitationpayload-generation+4
38 months ago
Previous1234567Next