Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
shellcode-x64 preview

shellcode-x64

GitHubhvictor/shellcode-x64

Shellcodes for Windows >= 11 x64

exploitationpayload-developmentpayload-generation+4
77 months ago
CVE-2003-0264_EXPLOIT preview

CVE-2003-0264_EXPLOIT

GitHubvrikodar/cve-2003-0264_exploit

Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3

binary-exploitationdebuggerseducation+5
5 years ago
CVE-2019-0232_tomcat_cgi_exploit preview

CVE-2019-0232_tomcat_cgi_exploit

GitHubx3m1sec/cve-2019-0232_tomcat_cgi_exploit

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

educationexploitationpayload-generation+3
1 year ago
zaphoxx-coldfusion preview

zaphoxx-coldfusion

GitHubzaphoxx/zaphoxx-coldfusion

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

exploitationpayload-generationpenetration-testing+3
26 years ago
Variatype.htb-CVE-2025-66034 preview

Variatype.htb-CVE-2025-66034

GitHubliquid1998/variatype.htb-cve-2025-66034

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

ctfexploitationpayload-generation+3
26 months ago
CVE-2020-8644-PlaySMS-1.4 preview

CVE-2020-8644-PlaySMS-1.4

GitHubh3rm1tr3b0rn/cve-2020-8644-playsms-1.4

Python script to exploit PlaySMS before 1.4.3

exploitationpayload-generationpenetration-testing+3
23 years ago
POC-CVE-2021-42013-EXPLOIT preview

POC-CVE-2021-42013-EXPLOIT

GitHubmakavellik/poc-cve-2021-42013-exploit

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

command-and-controlexploitationinformation-gathering+7
1 year ago
CVE-2025-6002 preview

CVE-2025-6002

GitHubschn1tzelme1ster/cve-2025-6002

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

exploitationpayload-generationpenetration-testing+3
6 months ago
CVE-2025-24893 preview

CVE-2025-24893

GitHubinfinit3i/cve-2025-24893

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered…

command-and-controlexploitationpayload-generation+3
61 year ago
CVE-2023-38035-MobileIron-RCE preview

CVE-2023-38035-MobileIron-RCE

GitHubmind2hex/cve-2023-38035-mobileiron-rce

Script to exploit CVE-2023-38035

exploitationpenetration-testingreconnaissance+3
13 years ago
CVE-2020-24186 preview

CVE-2020-24186

GitHubgazettel/cve-2020-24186

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…

exploitationpayload-generationpenetration-testing+4
1 year ago
cve-2018-9948-9958-exp preview

cve-2018-9948-9958-exp

GitHuborangepirate/cve-2018-9948-9958-exp

a exp for cve-2018-9948/9958 , current shellcode called win-calc

exploitationpayload-generationshellcode+3
8 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubl-urk/cve-2024-6387

Proof of concept python script for regreSSHion exploit.

binary-exploitationexploitationnetwork-security+6
121 year ago
cve-2023-42115 preview

cve-2023-42115

GitHubkirinse/cve-2023-42115

Python-based exploit and reverse shell payload generator for CVE-2023-42115, featuring scan and exploit modes with cross-platform payload creation.

exploitationpayload-developmentpayload-generation+3
92 years ago
CVE-2022-41544 preview

CVE-2022-41544

GitHubh3x0v3rl0rd/cve-2022-41544

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

exploitationpayload-generationpenetration-testing+3
1 year ago
chamilo-lms-unauthenticated-rce-poc preview

chamilo-lms-unauthenticated-rce-poc

GitHubcharchit-subedi/chamilo-lms-unauthenticated-rce-poc

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2024-10914-Exploit preview

CVE-2024-10914-Exploit

GitHubtamirido30/cve-2024-10914-exploit

CVE-2024-10914 Shell Exploit

command-and-controlexploitationpayload-generation+5
1 year ago
CVE-2018-8174 preview

CVE-2018-8174

GitHubsyfi/cve-2018-8174

MS Word MS WordPad via IE VBS Engine RCE

exploitationpayload-generationpenetration-testing+3
68 years ago
Previous12Next