Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
CVE-2024-36401-poc preview

CVE-2024-36401-poc

GitHubdelt-a/cve-2024-36401-poc

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

command-and-controlexploitationpenetration-testing+4
3 months ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubmrdottt/cve-2021-22911

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

exploitationpenetration-testingprivilege-escalation+3
3 years ago
CVE-2017-6079-Blind-Command-Injection-In-Edgewater-Edgemarc-Devices-Exploit preview

CVE-2017-6079-Blind-Command-Injection-In-Edgewater-Edgemarc-Devices-Exploit

GitHubmostafasoliman/cve-2017-6079-blind-command-injection-in-edgewater-edgemarc-devices-exploit

Exploit for CVE-2017-6079 blind command injection in Edgewater Edgemarc devices; reads remote files and uploads/executes ELF payloads via hidden…

exploitationremote-access-toolvulnerability-analysis+1
187 years ago
strapi_cms_3.0.0-beta.17.7 preview

strapi_cms_3.0.0-beta.17.7

GitHubhadrian3689/strapi_cms_3.0.0-beta.17.7

CVE-2019-18818/19606 Strapi RCE

educationexploitationpenetration-testing+3
3 years ago
CVE-2026-54806 preview

CVE-2026-54806

GitHubjoshuavanderpoll/cve-2026-54806

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

educationexploitationlabs-practice+5
122 months ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubcsenox/cve-2021-22911

Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1

exploitationpenetration-testingprivilege-escalation+3
613 years ago
cve-2017-12945 preview

cve-2017-12945

GitHubaress31/cve-2017-12945

Exploit for CVE-2017-12945.

command-and-controlexploitationpenetration-testing+3
46 years ago
sqlpad-rce-exploit-CVE-2022-0944 preview

sqlpad-rce-exploit-CVE-2022-0944

GitHub0xroqeeb/sqlpad-rce-exploit-cve-2022-0944

Python exploit for CVE-2022-0944 enabling blind remote code execution in SQLPad through the /api/test-connection endpoint with netcat callback.

exploitationpenetration-testingremote-access-tool+2
92 years ago
CVE-2026-57517 preview

CVE-2026-57517

GitHubshinthink/cve-2026-57517

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

exploitationpayload-developmentpenetration-testing+4
12 months ago
CVE-2022-25765 preview

CVE-2022-25765

GitHublordrna/cve-2022-25765

PoC for Blind RCE for CVE-2022-25765 (Tested in HTB - Precious Machine)

exploitationpenetration-testingremote-access-tool+2
33 years ago
JSshell preview

JSshell

GitHubshelld3v/jsshell

JSshell - JavaScript reverse/remote shell

payload-generationpenetration-testingremote-access-tool+1
6333 years ago
cve-2025-32433 preview

cve-2025-32433

GitHubjoshuavanderpoll/cve-2025-32433

Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.

educationexploitationpayload-development+3
36 months ago