Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
CVE-2024-23897 preview

CVE-2024-23897

GitHubslytechroot/cve-2024-23897

Jenkins RCE Arbitrary File Read CVE-2024-23897

exploitationpenetration-testingremote-access-tool+2
1 year ago
CVE-2019-12409 preview

CVE-2019-12409

GitHubmbadanoiu/cve-2019-12409

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

exploitationmisconfigurationpenetration-testing+3
1 year ago
java-stager preview

java-stager

GitHubcornerpirate/java-stager

A PoC Java Stager which can download, compile, and execute a Java file in memory.

command-and-controldynamic-code-analysiseducation+7
1078 years ago
cve-2021-22005-exp preview

cve-2021-22005-exp

GitHubshmilylty/cve-2021-22005-exp

Exploit for CVE-2021-22005, a pre-auth arbitrary file upload vulnerability in VMware vCenter Server, enabling remote code execution via webshell…

exploitationpenetration-testingremote-access-tool+2
1944 years ago
Shell3er preview

Shell3er

GitHubyehia-mamdouh/shell3er

PowerShell-based reverse shell with background task execution, file transfer, and dual persistence mechanisms via registry and startup folder for red…

command-and-controlpayload-generationpersistence-mechanisms+3
813 years ago
rapid7-CVE-2026-15409 preview

rapid7-CVE-2026-15409

GitHubremmons-r7/rapid7-cve-2026-15409

This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing…

exploitationpenetration-testingred-teaming+3
282 months ago
CVE-2022-30136 preview

CVE-2022-30136

GitHubfortra/cve-2022-30136

Windows Network File System Remote exploit for CVE-2022-30136

binary-exploitationexploitationpenetration-testing+2
143 years ago
CVE-2020-17518 preview

CVE-2020-17518

GitHubqmf0c3uk/cve-2020-17518

Python exploit for CVE-2020-17518, allowing arbitrary file write via Apache Flink REST API. Supports single target and batch scanning from a file.

data-exfiltrationexploitationremote-access-tool+2
75 years ago
log4j_RCE_CVE-2021-44832 preview

log4j_RCE_CVE-2021-44832

GitHubcckuailong/log4j_rce_cve-2021-44832

Proof-of-concept exploit for Log4j 2.17.0 RCE (CVE-2021-44832) using JNDI injection with malicious configuration file deployment.

command-and-controlexploitationpayload-generation+3
44 years ago
CVE-2023-33253 preview

CVE-2023-33253

GitHubtoxich4/cve-2023-33253

Proof-of-concept exploit for CVE-2023-33253, enabling authenticated remote code execution in LabCollector 6.0-6.15 via malicious PHP file upload.

exploitationpenetration-testingremote-access-tool+2
43 years ago
AgentDVR-5.1.6.0-File-Upload-and-Remote-Code-Execution preview

AgentDVR-5.1.6.0-File-Upload-and-Remote-Code-Execution

GitHuborange-418/agentdvr-5.1.6.0-file-upload-and-remote-code-execution

CVE-2024-22515 arbitrary file upload and CVE-2024-22514 remote code execution for AgentDVR 5.1.6.0 (Authenticated)

exploitationpayload-developmentpenetration-testing+3
52 years ago
CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE- preview

CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE-

GitHubfevar54/cve-2026-20253-splunk-enterprise-pre-auth-rce-

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

command-and-controlexploitationpayload-development+5
2 months ago
CVE-2020-10189-ManageEngine preview

CVE-2020-10189-ManageEngine

GitHubzavke/cve-2020-10189-manageengine

Python exploit for CVE-2020-10189 targeting ManageEngine Desktop Central, enabling unauthenticated remote code execution via file upload…

exploitationpenetration-testingremote-access-tool+2
35 years ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
5 months ago
CVE-2023-4220-RCE preview

CVE-2023-4220-RCE

GitHubbueno-armando/cve-2023-4220-rce

Python exploit for CVE-2023-4220, an unauthenticated remote code execution in Chamilo LMS via unrestricted file upload, enabling web shell deployment…

exploitationpenetration-testingremote-access-tool+2
11 year ago
Exploit-CVE-2024-23897 preview

Exploit-CVE-2024-23897

GitHubaadi0258/exploit-cve-2024-23897

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

exploitationpenetration-testingremote-access-tool+3
10 months ago
es_inject preview

es_inject

GitHubjeffgeiger/es_inject

Proof-of-concept exploit for CVE-2014-3120 Elasticsearch remote code execution, enabling file read and append on the host system via browser-based…

exploitationpenetration-testingremote-access-tool+2
12 years ago
Node.js-CVE-2024-39943 preview

Node.js-CVE-2024-39943

GitHubjenmrr/node.js-cve-2024-39943

Proof-of-concept exploit for CVE-2024-39943, demonstrating remote code execution via file upload in a Node.js HFS server using…

exploitationpenetration-testingremote-access-tool+2
1 year ago
Previous1…456…10Next