Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
679 results
CVE-2022-35405 preview

CVE-2022-35405

GitHubviniciuspereiras/cve-2022-35405

ManageEngine PAM360, Password Manager Pro, and Access Manager Plus unauthenticated remote code execution vulnerability PoC-exploit

exploitationpayload-generationpenetration-testing+3
31
4 years ago
Log4Shell-CVE-2021-44228-PoC preview

Log4Shell-CVE-2021-44228-PoC

GitHubpierpaolosestito-dev/log4shell-cve-2021-44228-poc

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

command-and-controlexploitationpayload-development+3
13 years ago
CVE-2018-14324-Exploit preview

CVE-2018-14324-Exploit

GitHubmatejsmycka/cve-2018-14324-exploit

Hacking Eclipse GlassFish - CVE-2018-14324

exploitationpayload-developmentpenetration-testing+3
10 months ago
CVE-2022-22963_Reverse-Shell-Exploit preview

CVE-2022-22963_Reverse-Shell-Exploit

GitHubj0ey17/cve-2022-22963_reverse-shell-exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify…

exploitationpayload-generationpenetration-testing+3
243 years ago
CVE-2026-33439-PoC preview

CVE-2026-33439-PoC

GitHubjonaschen0103/cve-2026-33439-poc

Python PoC exploiting CVE-2026-33439, a pre-auth RCE in OpenAM via Java deserialization of the jato.clientSession parameter, with interactive and…

exploitationpayload-generationpenetration-testing+4
9 days ago
CVE-2015-5377 preview

CVE-2015-5377

GitHubfi3ro/cve-2015-5377

Java deserialization exploit targeting Elasticsearch 1.5.2 transport protocol (port 9300) using Groovy MethodClosure chain for remote code execution…

exploitationpayload-developmentremote-access-tool+2
34 years ago
CVE-2022-41678 preview

CVE-2022-41678

GitHuburjack2025/cve-2022-41678

CVE-2022-41678 是 Apache ActiveMQ 中的一个远程代码执行漏洞。该漏洞允许攻击者通过 JMX (Java Management Extensions) 接口修改 Log4j 配置或 JFR (Java Flight Recorder) 配置,从而写入恶意的 JSP…

exploitationpayload-generationpenetration-testing+3
211 months ago
cve-2023-30990 preview

cve-2023-30990

GitHubcyn8/cve-2023-30990

IBM i DDM Unauthenticated RCE - Java Reverse Shell

exploitationpayload-generationpenetration-testing+3
7 months ago
Weblogic_CVE-2020-14645 preview

Weblogic_CVE-2020-14645

GitHubjlvsjp/weblogic_cve-2020-14645

Java PoC for WebLogic CVE-2020-14645 Coherence deserialization RCE. Hosts a malicious class via LDAP and triggers remote code execution on vulnerable…

exploitationpayload-developmentpenetration-testing+4
6 years ago
CVE-2019-12409 preview

CVE-2019-12409

GitHubjas502n/cve-2019-12409

Apache Solr RCE (ENABLE_REMOTE_JMX_OPTS="true")

exploitationpayload-generationpenetration-testing+3
1046 years ago
CVE-2018-3191 preview

CVE-2018-3191

GitHublibraggbond/cve-2018-3191

CVE-2018-3191 反弹shell

command-and-controlexploitationpayload-generation+3
637 years ago
CVE-2019-2890 preview

CVE-2019-2890

GitHubjas502n/cve-2019-2890

Exploit for CVE-2019-2890 WebLogic deserialization RCE with ysoserial integration, providing step-by-step PoC for remote code execution via T3…

exploitationpayload-developmentpenetration-testing+3
446 years ago
WebSphere-WSIF-gadget preview

WebSphere-WSIF-gadget

GitHubsilentsignal/websphere-wsif-gadget

CVE-2020-4464 / CVE-2020-4450

exploitationpayload-developmentpenetration-testing+3
365 years ago
CVE-2022-26134_Behinder_MemShell preview

CVE-2022-26134_Behinder_MemShell

GitHubmaskcybersecurityteam/cve-2022-26134_behinder_memshell

Java-based exploit for CVE-2022-26134 that deploys a Behinder memory shell on vulnerable Atlassian Confluence servers for remote command execution.

command-and-controlexploitationpayload-generation+3
83 years ago
struts2-tool preview

struts2-tool

GitHubgu-007/struts2-tool

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

command-and-controlexploitationpayload-development+5
126 days ago
ActiveMQ_CVE-2015-5254 preview

ActiveMQ_CVE-2015-5254

GitHubma1dong/activemq_cve-2015-5254

ActiveMQ_CVE-2015-5254

exploitationpayload-generationremote-access-tool+2
26 years ago
Jmeter-CVE-2018-1297- preview

Jmeter-CVE-2018-1297-

GitHub48484848484848/jmeter-cve-2018-1297-

Dockerized vulnerable Apache JMeter RMI environment for CVE-2018-1297 deserialization RCE, with ysoserial exploit commands, verification, and…

command-and-controlexploitationpayload-generation+3
2 years ago
etaHEN preview

etaHEN

GitHubetahen/etahen

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

binary-exploitationexploitationpayload-development+3
6844 months ago
Previous12…38Next