Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
164 results
CVE-2021-41773 preview

CVE-2021-41773

GitHubgunzf0x/cve-2021-41773

Python-based proof-of-concept exploit for CVE-2021-41773, enabling remote code execution on Apache 2.4.49 servers with custom command and port…

exploitationpenetration-testingred-teaming+3
11 months ago
-2-CVE-2019-0708 preview

-2-CVE-2019-0708

GitHubulisesrc/-2-cve-2019-0708
binary-exploitationexploitationpenetration-testing+3
16 years ago
CVE-2023-36845-Juniper-Vulnerability preview

CVE-2023-36845-Juniper-Vulnerability

GitHub0xnehru/cve-2023-36845-juniper-vulnerability

This Python script automates the Proof of Concept (PoC) for CVE-2023-36845, a vulnerability impacting Juniper Networks Junos OS on EX and SRX Series…

exploitationpenetration-testingred-teaming+3
12 years ago
CVE-2025-53770-SharePoint-Deserialization-RCE-PoC preview

CVE-2025-53770-SharePoint-Deserialization-RCE-PoC

GitHubharryhaxor/cve-2025-53770-sharepoint-deserialization-rce-poc

A critical vulnerability in Microsoft SharePoint Server allows unauthenticated remote code execution via deserialization of untrusted data. Microsoft…

exploitationpenetration-testingred-teaming+3
11 year ago
react2shell preview

react2shell

GitHubxkey8/react2shell

PoC for React2Shell (CVE-2025-55182)

exploitationpenetration-testingred-teaming+3
19 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubluoluoqingge/cve-2025-55182

Pre-authentication remote code execution exploit for React Server Components and Next.js via deserialization vulnerability. Supports single-target…

exploitationpenetration-testingred-teaming+3
16 months ago
ssh_poc2024 preview

ssh_poc2024

GitHubalex14324/ssh_poc2024

An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server

binary-exploitationexploitationpenetration-testing+3
12 years ago
CVE-2026-22444 preview

CVE-2026-22444

GitHubbfdfhdsfdd-crypto/cve-2026-22444

Exploit for Apache Solr CVE-2026-22444, leveraging UNC path injection and SMB server to achieve remote code execution via malicious configset and…

exploitationpenetration-testingred-teaming+3
8 months ago
salt-rce-scanner-CVE-2020-11651-CVE-2020-11652 preview

salt-rce-scanner-CVE-2020-11651-CVE-2020-11652

GitHubappcheck-ng/salt-rce-scanner-cve-2020-11651-cve-2020-11652

Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.

command-and-controlexploitationpenetration-testing+3
15 years ago
CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001 preview

CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001

GitHubninjazan420/cve-2025-52691-poc-smartermail-authentication-bypass-exploit-wt-2026-0001

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

authenticationexploitationpenetration-testing+4
8 months ago
Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725 preview

Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725

GitHubloursha/oracle-weblogic-server-asyncresponseservice-deserialization-remote-code-execution-cve-2019-2725

Unauthenticated remote code execution exploit for Oracle WebLogic Server (CVE-2019-2725) via deserialization in AsyncResponseService, delivering a…

exploitationpenetration-testingred-teaming+3
8 months ago
RCE-CVE-2025-3248 preview

RCE-CVE-2025-3248

GitHubtiemio/rce-cve-2025-3248

This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required…

exploitationpayload-developmentpenetration-testing+3
11 year ago
CVE-2025-26686-poc-A-critical-RCE-vulnerability-in-Windows-TCP-IP-stack preview

CVE-2025-26686-poc-A-critical-RCE-vulnerability-in-Windows-TCP-IP-stack

GitHubcyghtinc/cve-2025-26686-poc-a-critical-rce-vulnerability-in-windows-tcp-ip-stack

POC for CVE-2025-26686 - A critical RCE vulnerability in Windows TCP/IP stack (CVE-2025-26686) leaves sensitive memory unlocked, allowing remote…

exploitationpayload-developmentpenetration-testing+3
10 months ago
regreSSHion preview

regreSSHion

GitHubteamos-hub/regresshion

This is a POC I wrote for CVE-2024-6387

binary-exploitationexploitationpenetration-testing+3
12 years ago
CVE-2021-26084 preview

CVE-2021-26084

GitHubcrackercat/cve-2021-26084

Atlassian Confluence Pre-Auth RCE

exploitationpenetration-testingred-teaming+3
5 years ago
CVE-2025-8110-Gogs-RCE-Exploit preview

CVE-2025-8110-Gogs-RCE-Exploit

GitHubadityainnovates/cve-2025-8110-gogs-rce-exploit

Gogs CVE-2025-8110 RCE Exploit

exploitationpenetration-testingred-teaming+3
5 months ago
CVE-2019-0708-RCE preview

CVE-2019-0708-RCE

GitHubzoujialan/cve-2019-0708-rce

CVE-2019-0708-RCE

exploitationpenetration-testingred-teaming+2
7 years ago
CVE-2025-3248 preview

CVE-2025-3248

GitHub0xgh057r3c0n/cve-2025-3248

Exploit for Langflow AI Remote Code Execution (Unauthenticated)

ai-securityeducationexploitation+3
1 year ago
Previous1…78910Next