Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
CVE-2026-18937 preview

CVE-2026-18937

GitHubabraxas/cve-2026-18937

Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before…

educationexploitationpenetration-testing+4
3 days ago
CVE-2026-77991 preview

CVE-2026-77991

GitHubabraxas/cve-2026-77991

Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

educationexploitationlabs-practice+6
13 days ago
cve-2024-6387-poc preview

cve-2024-6387-poc

GitHubdimamend/cve-2024-6387-poc

Exploit for CVE-2024-6387, a signal handler race condition in OpenSSH sshd, enabling remote code execution as root on glibc-based Linux systems.

binary-exploitationexploitationpenetration-testing+3
2 years ago
CVE-2024-6387_poc preview

CVE-2024-6387_poc

GitHubjocker2410/cve-2024-6387_poc

Proof-of-concept exploit for CVE-2024-6387, a signal handler race condition in OpenSSH server (sshd) on glibc-based Linux systems, enabling remote…

exploitationpenetration-testingprivilege-escalation+3
2 years ago
webmin_cve-2019-12840_poc preview

webmin_cve-2019-12840_poc

GitHubkre80r/webmin_cve-2019-12840_poc

A standalone POC for CVE-2019-12840

exploitationpayload-generationpenetration-testing+3
86 years ago
ssh_poc2024 preview

ssh_poc2024

GitHubalex14324/ssh_poc2024

An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server

binary-exploitationexploitationpenetration-testing+3
12 years ago
cve-2024-6387-poc preview

cve-2024-6387-poc

GitHubt3rry327/cve-2024-6387-poc

Exploit for CVE-2024-6387 targeting a signal handler race condition in OpenSSH sshd on glibc-based Linux systems, enabling remote code execution as…

binary-exploitationexploitationpenetration-testing+2
2 years ago
cve-2024-6387-poc preview

cve-2024-6387-poc

GitHublflare/cve-2024-6387-poc

MIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc

binary-exploitationexploitationpenetration-testing+2
1282 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubd0rb/cve-2024-6387

Multithreaded Python exploit for OpenSSH CVE-2024-6387 RCE vulnerability, leveraging a signal handler race condition to achieve root access on target…

educationexploitationpayload-development+3
522 years ago
cve-2024-6387-poc preview

cve-2024-6387-poc

GitHubacrono/cve-2024-6387-poc

32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc

binary-exploitationexploitationpenetration-testing+2
3752 years ago
CVE-2021-24307-all-in-one-seo-pack-admin-rce preview

CVE-2021-24307-all-in-one-seo-pack-admin-rce

GitHubdarkpills/cve-2021-24307-all-in-one-seo-pack-admin-rce

Proof-of-concept exploit for CVE-2021-24307, an authenticated admin RCE in All in One SEO Pack <= 4.1.0.1 via PHP unserialization, enabling arbitrary…

exploitationpayload-generationpenetration-testing+3
44 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubprelearn-code/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

command-and-controlexploitationpayload-development+4
22 years ago
CVE-2026-86218 preview

CVE-2026-86218

GitHubsuper-meuw/cve-2026-86218

Python 3 proof-of-concept exploit for CVE-2026-86218, a pre-auth RCE in N-able N-central via a Struts multipart race condition, with command…

exploitationpayload-developmentpenetration-testing+5
11 days ago
PHP-REVERSE-SHELL preview

PHP-REVERSE-SHELL

GitLabs_r_e_e_r_a_j/php-reverse-shell

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

command-and-controleducationids-ips-evasion+6
11 year ago
cve-2024-6387_AImade preview

cve-2024-6387_AImade

GitHubhssmo/cve-2024-6387_aimade

Python script to test CVE-2024-6387 OpenSSH race condition vulnerability, enabling remote code execution on glibc-based Linux systems for security…

educationexploitationpenetration-testing+2
2 years ago
CVE-2025-32432-exploit-by-P34NUT preview

CVE-2025-32432-exploit-by-P34NUT

GitHubp34nut2/cve-2025-32432-exploit-by-p34nut

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

exploitationpayload-developmentpenetration-testing+6
717 days ago
ddoor preview

ddoor

GitHubrek7/ddoor

DDoor - cross platform backdoor using dns txt records

anti-botcommand-and-controldns-analysis+5
305 years ago
iPwn preview

iPwn

GitHubbrows3r/ipwn

A Framework meant for the exploitation of iOS devices.

exploitationios-securitymobile-security+5
2345 years ago
Previous12Next