Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
57 results
CVE-2021-42013 preview

CVE-2021-42013

GitHubasepsaepdin/cve-2021-42013

Exploit for Apache 2.4.49/2.4.50 path traversal and RCE (CVE-2021-42013). Includes Docker setup and script to test path traversal, execute commands,…

educationexploitationlabs-practice+3
1 year ago
cve-2021-41773 preview

cve-2021-41773

GitHubmightysai1997/cve-2021-41773

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution (CVE-2021-41773). Includes Docker-based reproduction…

educationexploitationpenetration-testing+3
4 years ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubcc3305/cve-2025-49844

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua scripting enabling remote code execution. Targets specific Redis…

binary-exploitationeducationexploitation+3
3 months ago
CVE-2020-15778 preview

CVE-2020-15778

GitHubyifanzhg/cve-2020-15778

Reproduces CVE-2020-15778 SCP command injection exploit with Docker-based client-server setup for testing remote code execution and reverse shell…

command-and-controlcontainer-securityexploitation+3
33 years ago
CVE-2024-25082 preview

CVE-2024-25082

GitHubmoamenx8/cve-2024-25082

Proof-of-concept exploit for CVE-2024-25082, demonstrating remote code execution in FontForge via crafted ZIP archives. Includes payload generator,…

educationexploitationpayload-generation+3
6 months ago
CVE-2025-32433-PoC preview

CVE-2025-32433-PoC

GitHubniteeshpujari/cve-2025-32433-poc

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

ctfeducationexploitation+3
71 year ago
CVE-2019-15642 preview

CVE-2019-15642

GitHubjas502n/cve-2019-15642

Authenticated remote code execution exploit for Webmin (CVE-2019-15642). Provides a Python script to execute arbitrary commands on vulnerable Webmin…

command-and-controlexploitationpenetration-testing+3
337 years ago
wardgate preview

wardgate

GitHubwardgate/wardgate

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

api-securityauthentication-authorizationcloud-security+8
1366 months ago
poc-2025-9074 preview

poc-2025-9074

GitHubxwpdx0/poc-2025-9074

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

cloud-infrastructure-securitycommand-and-controlcontainer-security+7
49 months ago
CVE-2017-11610 preview

CVE-2017-11610

GitHubdungsocool/cve-2017-11610

Step-by-step exploit writeup for CVE-2017-11610 (Supervisord XML-RPC RCE) with attack surface analysis, namespace traversal discovery, and…

educationexploitationlabs-practice+4
4 months ago
Erlang-OTP-PoC_CVE-2025-32433 preview

Erlang-OTP-PoC_CVE-2025-32433

GitHubantoniesoga/erlang-otp-poc_cve-2025-32433

Proof-of-concept exploit for CVE-2025-32433, an Erlang/OTP SSH pre-authentication channel confusion vulnerability, demonstrating authentication…

educationexploitationpenetration-testing+2
28 months ago
AutoSploit preview

AutoSploit

GitHubnullarray/autosploit

Automated Mass Exploiter

command-and-controlexploit-frameworksinformation-gathering+5
5.3k6 years ago
exploit-CVE-2017-7494 preview

exploit-CVE-2017-7494

GitHubopsxcq/exploit-cve-2017-7494

SambaCry exploit and vulnerable container (CVE-2017-7494)

container-securityexploitationpayload-development+3
3803 years ago
tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE preview

tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE

GitHub4qu4r1um/tugtainer-1.30.2-cve-2026-55494-and-cve-2026-62308-to-rce

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

container-escapecontainer-securityeducation+5
2 months ago
CVE-2025-55182_liyon preview

CVE-2025-55182_liyon

GitHubhujiaozhuzhu/cve-2025-55182_liyon

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

command-and-controleducationexploitation+7
5 months ago
CVE-2022-22963-POC preview

CVE-2022-22963-POC

GitHubiliass-dahman/cve-2022-22963-poc

Exploit for CVE-2022-22963 (Spring Cloud Function SpEL injection) enabling remote code execution and reverse shell. Includes Docker-based lab for…

educationexploitationlabs-practice+3
43 years ago
php-reverse-shell preview

php-reverse-shell

GitHubivan-sincek/php-reverse-shell

PHP shells that work on Linux OS, macOS, and Windows OS.

educationexploitationpenetration-testing+4
5747 months ago
CVE-2026-PoCs preview

CVE-2026-PoCs

GitHubsecurewithumer/cve-2026-pocs

A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.

curated-resourceseducationexploitation+5
5318h 45m ago
Previous1234Next