Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
CVE-2025-43990-Magento-RCE preview

CVE-2025-43990-Magento-RCE

GitHubamkkk221/cve-2025-43990-magento-rce

Magento APSB25-94 Unauthenticated File Upload to RCE (CVE-2026-XXXX) - Eval Shell + Probe Scanner

exploitationpayload-generationpenetration-testing+4
4 months ago
CVE-2024-51793 preview

CVE-2024-51793

GitHubktn1990/cve-2024-51793

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

code-analysisexploitationpayload-generation+6
17 months ago
CVE-2025-52691-poc preview

CVE-2025-52691-poc

GitHubrimbadirgantara/cve-2025-52691-poc

Proof-of-concept exploit for CVE-2025-52691: unauthenticated arbitrary file upload leading to RCE in SmarterMail. Includes vulnerability scanner,…

educationexploitationpayload-generation+5
38 months ago
CVE-2024-10793 preview

CVE-2024-10793

GitHubmahajian/cve-2024-10793

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

exploitationpayload-developmentprivilege-escalation+3
21 year ago
OpenSTAManager-RCE-Exploit-CVE-2026-38751 preview

OpenSTAManager-RCE-Exploit-CVE-2026-38751

GitHubb0ysie7e/openstamanager-rce-exploit-cve-2026-38751

OpenSTAManager-RCE-Exploit-CVE-2026-38751

educationexploitationpayload-development+5
82 months ago
BOF_ExecuteAssembly preview

BOF_ExecuteAssembly

GitHubntdallas/bof_executeassembly

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

binary-exploitationcommand-and-controlids-ips-evasion+4
1978 months ago
CVE-2025-29009 preview

CVE-2025-29009

GitHubnxploited/cve-2025-29009

WordPress Medical Prescription Attachment Plugin for WooCommerce Plugin <= 1.2.3 is vulnerable to a high priority Arbitrary File Upload

educationexploitationpayload-generation+4
14 months ago
CVE-2024-50986 preview

CVE-2024-50986

GitHubriftsandroses/cve-2024-50986

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

binary-exploitationexploitationpayload-generation+4
1 year ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
2091 month ago
0-click-RCE-Exploit-for-CVE-2024-50526 preview

0-click-RCE-Exploit-for-CVE-2024-50526

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50526

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

exploitationpayload-generationpenetration-testing+5
37 months ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
15 months ago
Clematis preview

Clematis

GitHubcblabresearch/clematis

PE to shellcode

exploitationpayload-developmentpayload-generation+3
2861 year ago
artifacts-kit preview

artifacts-kit

GitHubforrest-orr/artifacts-kit

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

exploitationforensicsmalware-analysis+5
2312 years ago
CVE-2024-56249 preview

CVE-2024-56249

GitHubnxploited/cve-2024-56249

WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability

exploitationpayload-generationpenetration-testing+4
11 year ago
CVE-2023-46818 preview

CVE-2023-46818

GitHubengranaabubakar/cve-2023-46818

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

code-analysisexploitationpayload-generation+4
1 year ago
CVE-2006-3592 preview

CVE-2006-3592

GitHubadenkiewicz/cve-2006-3592

Exploit for Easy File Sharing FTP Server 3.5 on Win7 32

binary-exploitationexploitationpayload-generation+3
7 years ago
CVE-2020-9484 preview

CVE-2020-9484

GitHubpentestical/cve-2020-9484

Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

educationexploitationpayload-generation+3
354 years ago
Previous1234Next