Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1405 results
CVE-2021-31761 preview

CVE-2021-31761

GitHubmesh3l911/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

exploitationpenetration-testingremote-access-tool+2
5
5 years ago
CVE-2023-41425-WonderCMS-Authenticated-RCE preview

CVE-2023-41425-WonderCMS-Authenticated-RCE

GitHubdiegomjx/cve-2023-41425-wondercms-authenticated-rce

Xss injection, WonderCMS 3.2.0 -3.4.2

educationexploitationpayload-generation+4
11 month ago
WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425 preview

WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425

GitHub0xdtc/wondercms-4.3.2-xss-to-rce-exploits-cve-2023-41425

CVE-2023-41425 Refurbish

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubambalabanov/cve-2020-9496

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

exploitationpayload-generationpenetration-testing+3
5 years ago
CVE-2023-41425 preview

CVE-2023-41425

GitHubprodigiousmind/cve-2023-41425

WonderCMS Authenticated RCE - CVE-2023-41425

exploitationpayload-generationphishing+3
271 year ago
ez-iRZ preview

ez-iRZ

GitHubsakurasamuraii/ez-irz

Exploit for CVE-2022-27226

exploitationpenetration-testingremote-access-tool+2
154 years ago
CVE-2021-31762 preview

CVE-2021-31762

GitHubmesh3l911/cve-2021-31762

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

command-and-controlexploitationpenetration-testing+3
15 years ago
Thunderstorm preview

Thunderstorm

GitHubjoelgmsec/thunderstorm

Modular framework to exploit UPS devices

exploitationexploit-frameworkshardware-iot-security+4
653 years ago
WP2Shell preview

WP2Shell

GitHubg0d150ne/wp2shell

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

exploitationexploit-frameworkspayload-development+7
12 months ago
novahot preview
Archived

novahot

GitHubchrisallenlane/novahot

A webshell framework for penetration testers.

command-and-controlexploit-frameworkspayload-generation+3
2981 year ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubfrostsaberx/cve-2019-0708

CVE-2019-0708 With Metasploit-Framework Exploit

exploitationexploit-frameworkspenetration-testing+3
47 years ago
mec preview

mec

GitHubjm33-m0/mec

for mass exploiting

exploitationexploit-frameworksinformation-gathering+5
6144 years ago
Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit preview

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

GitHub34zy/microsoft-office-word-mshtml-remote-code-execution-exploit

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

exploitationexploit-frameworkspayload-development+4
654 years ago
Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201 preview

Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201

GitHubjgoyd/glass-cage-ios18-cve-2025-24085-cve-2025-24201

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…

exploitationexploit-frameworksios-security+8
419 months ago
CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit preview

CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit

GitHubakucybersec/cve-2022-1329-wordpress-elementor-3.6.0-3.6.1-3.6.2-remote-code-execution-exploit

Exploit for CVE-2022-1329, a WordPress Elementor plugin RCE vulnerability, allowing authenticated users to upload and execute arbitrary PHP files via…

exploit-frameworkspayload-developmentpenetration-testing+3
234 years ago
CVE-2019-0708-EXP-MSF- preview

CVE-2019-0708-EXP-MSF-

GitHubqing-root/cve-2019-0708-exp-msf-

CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708

exploitationexploit-frameworkspenetration-testing+3
117 years ago
apache_normalize_path preview

apache_normalize_path

GitHubzeop-cybersec/apache_normalize_path

Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)

exploit-frameworkspayload-developmentpenetration-testing+3
124 years ago
CVE-2017-7269 preview

CVE-2017-7269

GitHubal1ex/cve-2017-7269

Exploit for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution. Designed for use with Metasploit in penetration…

exploit-frameworkspenetration-testingremote-access-tool+2
118 years ago
Previous12…79Next