Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
CVE-2026-49049 preview

CVE-2026-49049

GitHubmatakucing-ofc/cve-2026-49049

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

exploitationpenetration-testingremote-access-tool+4
3 days ago
p0wny-shell preview

p0wny-shell

GitHubflozz/p0wny-shell

Single-file PHP shell

penetration-testingremote-access-toolweb-application-exploitation
2.9k1 year ago
CVE-2020-14008 preview

CVE-2020-14008

GitHub0x0d3ad/cve-2020-14008

CVE-2020-14008 - ManageEngine Applications Manager RCE

exploitationpayload-developmentpenetration-testing+3
34 months ago
CVE-2022-41678 preview

CVE-2022-41678

GitHubmbadanoiu/cve-2022-41678

CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ

data-exfiltrationexploitationremote-access-tool+2
21 year ago
CVE-2025-60787_PoC preview

CVE-2025-60787_PoC

GitHublil0xplorer/cve-2025-60787_poc

Authenticated RCE exploit for MotionEye <= 0.43.1b4 via client-side validation bypass on the image_file_name field. Includes reverse shell payload…

exploitationpenetration-testingred-teaming+3
26 months ago
CVE-2024-12252 preview

CVE-2024-12252

GitHubnxploited/cve-2024-12252

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2025-64155 preview

CVE-2025-64155

GitHubhorizon3ai/cve-2025-64155

CVE-2025-64155: Fortinet FortiSIEM Argument Injection to Remote Code Execution

educationexploitationpayload-development+3
338 months ago
Python-exploit-CVE-2020-25213 preview

Python-exploit-CVE-2020-25213

GitHubbly-coder/python-exploit-cve-2020-25213

Python exploit for RCE in Wordpress

exploitationpayload-generationpenetration-testing+3
63 years ago
CVE-2023-422-Chamilo-LMS-RCE preview

CVE-2023-422-Chamilo-LMS-RCE

GitHubhusenjandev/cve-2023-422-chamilo-lms-rce

Remote Code Execution for Chamilo LMS

exploitationpayload-generationremote-access-tool+2
2 years ago
PSAsyncShell preview

PSAsyncShell

GitHubjoelgmsec/psasyncshell

Asynchronous TCP reverse shell in pure PowerShell that bypasses firewalls via non-blocking I/O, with command history, file upload/download, and…

command-and-controlids-ips-evasionpayload-generation+1
1579 months ago
CVE-2024-21546 preview

CVE-2024-21546

GitHubajdumanhug/cve-2024-21546

This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions…

exploitationpayload-generationpenetration-testing+3
51 year ago
n8n-cve-2025-68613 preview

n8n-cve-2025-68613

GitHubgagaltotal/n8n-cve-2025-68613

Authenticated RCE exploit PoC and vulnerability scanner for CVE-2025-68613 in n8n. Supports command execution, file operations, and reverse shell…

command-and-controleducationexploitation+5
8 months ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubktn1990/cve-2024-5084

WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpayload-generationpenetration-testing+3
2 years ago
loki preview

loki

GitHubnccgroup/loki

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

data-exfiltrationlateral-movementpenetration-testing+3
6310 years ago
CVE-2024-3912 preview

CVE-2024-3912

GitHubh4rk3nz0/cve-2024-3912

Asus Router Arbitrary File Write to Remote Code Execution PoC - Fk Mirai

educationexploitationhardware-security+4
6 months ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubraeezrbr/cve-2024-5084

Exploit for CVE-2024-5084: unauthenticated arbitrary file upload in Hash Form WordPress plugin, enabling remote code execution via Python script with…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-0757-Exploit preview

CVE-2024-0757-Exploit

GitHubhunthubspace/cve-2024-0757-exploit

A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)

exploitationpayload-generationpenetration-testing+3
82 years ago
CVE-2020-0796 preview

CVE-2020-0796

GitHuborangmuda/cve-2020-0796

Remote Code Execution POC for CVE-2020-0796

educationexploitationpayload-development+3
54 years ago
Previous1…567…10Next