Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
CVE-2017-13089 preview

CVE-2017-13089

GitHubmzeyong/cve-2017-13089

CVE-2017-13089

exploitationpayload-generationpenetration-testing+2
558 years ago
cve-2022-29464 preview

cve-2022-29464

GitHublowkey0808/cve-2022-29464

Python exploit for CVE-2022-29464 targeting WSO2 web servers with automated webshell upload and command execution capabilities.

exploitationpayload-generationpenetration-testing+3
4 years ago
SpringFramework_CVE-2022-22965_RCE preview

SpringFramework_CVE-2022-22965_RCE

GitHubxsxtw/springframework_cve-2022-22965_rce

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

exploitationpayload-generationpenetration-testing+3
4 years ago
Drupalgeddon2 preview

Drupalgeddon2

GitHubruthvikvegunta/drupalgeddon2

CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE

exploitationpayload-generationpenetration-testing+3
6 years ago
CVE-2019-11447_reverse_shell_upload preview

CVE-2019-11447_reverse_shell_upload

GitHubsubsting/cve-2019-11447_reverse_shell_upload

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

exploitationpayload-generationpenetration-testing+3
2 years ago
WordPress-HT-Contact-CVE-2025-7340-RCE preview

WordPress-HT-Contact-CVE-2025-7340-RCE

GitHubkai-one001/wordpress-ht-contact-cve-2025-7340-rce

Python exploit for CVE-2025-7340, an unauthenticated file upload vulnerability in the WordPress HT Contact Form widget, enabling remote code…

exploitationpayload-generationpenetration-testing+3
1 year ago
zaphoxx-coldfusion preview

zaphoxx-coldfusion

GitHubzaphoxx/zaphoxx-coldfusion

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

exploitationpayload-generationpenetration-testing+3
25 years ago
Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE preview

Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE

GitHubrandallbanner/spring-cloud-function-vulnerability-cve-2022-22963-rce

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

exploitationpayload-generationpenetration-testing+3
43 years ago
CVE-2020-8644-PlaySMS-1.4 preview

CVE-2020-8644-PlaySMS-1.4

GitHubh3rm1tr3b0rn/cve-2020-8644-playsms-1.4

Python script to exploit PlaySMS before 1.4.3

exploitationpayload-generationpenetration-testing+3
23 years ago
0-click-RCE-Exploit-for-CVE-2024-50498 preview

0-click-RCE-Exploit-for-CVE-2024-50498

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50498

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

exploitationpayload-generationpenetration-testing+5
18 months ago
0-click-RCE-Exploit-for-CVE-2024-50526 preview

0-click-RCE-Exploit-for-CVE-2024-50526

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50526

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

exploitationpayload-generationpenetration-testing+5
38 months ago
Larascript preview

Larascript

GitHubpwnedshell/larascript

Laravel RCE exploit. CVE-2018-15133

exploitationpayload-generationremote-access-tool+3
354 years ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubwearehackers160/cve-2026-48907

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

exploitationpayload-generationpenetration-testing+3
3 months ago
CVE-2025-6002 preview

CVE-2025-6002

GitHubschn1tzelme1ster/cve-2025-6002

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

exploitationpayload-generationpenetration-testing+3
6 months ago
CVE-2025-32206 preview

CVE-2025-32206

GitHubnxploited/cve-2025-32206

WordPress Processing Projects Plugin <= 1.0.2 is vulnerable to Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
21 year ago
CVE-2023-46604-RCE preview

CVE-2023-46604-RCE

GitHubreggyraider/cve-2023-46604-rce

CVE-2023-46604-RCE exploit with Linux reverse shell payload

exploitationpayload-generationremote-access-tool+3
3 months ago
CVE-2022-40471 preview

CVE-2022-40471

GitHubrashidkhanpathan/cve-2022-40471

RCE Exploit and Research

exploitationpayload-generationpenetration-testing+3
103 years ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubp1ckzi/cve-2022-22965

spring4shell | CVE-2022-22965

exploitationpayload-generationpenetration-testing+3
234 years ago
Previous123Next