Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
CVE-2023-41425-WonderCMS-Authenticated-RCE preview

CVE-2023-41425-WonderCMS-Authenticated-RCE

GitHubdiegomjx/cve-2023-41425-wondercms-authenticated-rce

Xss injection, WonderCMS 3.2.0 -3.4.2

educationexploitationpayload-generation+4
1
6 days ago
File-Tunnel preview

File-Tunnel

GitHubfiddyschmitt/file-tunnel

Tunnel TCP connections through a file

ids-ips-evasionlateral-movementnetwork-mapping+3
1.1k10 days ago
CVE-2023-24489-ShareFile preview

CVE-2023-24489-ShareFile

GitHubadhikara13/cve-2023-24489-sharefile

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

command-and-controlexploitationpenetration-testing+3
133 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubsoliux/cve-2021-41773

On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit…

exploitationpenetration-testingremote-access-tool+2
24 years ago
CVE-2022-26809 preview

CVE-2022-26809

GitHubwebsecnl/cve-2022-26809

Remote Code Execution Exploit in the RPC Library

binary-exploitationexploitationpenetration-testing+2
284 years ago
snmp-shell preview

snmp-shell

GitHubmxrch/snmp-shell

Shell Simulation over Net-SNMP with extend functionality

command-and-controlexploitationnetwork-security+3
995 years ago
ioscpy preview

ioscpy

GitHublautarovculic/ioscpy

Now you can mirror and control your jailbroken iPhone over USB

information-gatheringios-securitymobile-security+3
1992 months ago
mqxss preview

mqxss

GitHubgrampae/mqxss

Hooked browser communication over MQTT

command-and-controlinformation-gatheringpayload-generation+4
82 years ago
CVE-2024-24590 preview

CVE-2024-24590

GitHubjunnythemarksman/cve-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously…

exploitationpayload-generationpenetration-testing+3
12 years ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Weaponized web shell

penetration-testingpost-exploitationprivilege-escalation+4
3.5k11 months ago
CVE-2021-27651 preview

CVE-2021-27651

GitHuborangmuda/cve-2021-27651

bypass all stages of the password reset flow

authenticationcode-analysisexploitation+3
14 years ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k14h 9m ago
CVE-2026-23744-PoC preview

CVE-2026-23744-PoC

GitHubboroeurnprach/cve-2026-23744-poc

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by…

exploitationpayload-generationpenetration-testing+3
103 months ago
Webmin_Exploit_reverse_shell preview
Archived

Webmin_Exploit_reverse_shell

GitHubbytereaper77/webmin_exploit_reverse_shell

A simple C-based vulnerability in Webmin versions 1.890 to 1.920

binary-exploitationexploitationpayload-development+4
21 year ago
Chamilo-CVE-2023-4220-Exploit preview

Chamilo-CVE-2023-4220-Exploit

GitHubziad-sakr/chamilo-cve-2023-4220-exploit

This is an Exploit for Unrestricted file upload in big file upload functionality in Chamilo-LMS for this location…

exploitationpayload-generationpenetration-testing+3
52 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubgotr00t0day/cve-2022-1388

A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit…

authentication-authorizationexploitationpenetration-testing+3
72 years ago
Malicious-MCP preview

Malicious-MCP

GitHubquinnbast/malicious-mcp

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

ai-securitycommand-and-controldata-exfiltration+8
85 months ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
Previous12345Next