Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
133 results
Foxit-Reader-RCE-with-virualalloc-and-shellcode-for-CVE-2018-9948-and-CVE-2018-9958 preview

Foxit-Reader-RCE-with-virualalloc-and-shellcode-for-CVE-2018-9948-and-CVE-2018-9958

GitHubmanojcode/foxit-reader-rce-with-virualalloc-and-shellcode-for-cve-2018-9948-and-cve-2018-9958

Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap

binary-exploitationexploitationpayload-development+3
6
8 years ago
WinAPRS-Exploits preview

WinAPRS-Exploits

GitHubcoalfire-research/winaprs-exploits

A collection of exploits, shellcode, and tools related to CVE-2022-24702

exploitationpayload-developmentpenetration-testing+3
94 years ago
CVE-2025-2783 preview

CVE-2025-2783

GitHubeliangonzi00/cve-2025-2783

Full-chain RCE exploit for CVE-2025-2783, a Chromium Ipcz sandbox escape vulnerability. Implements thread hijacking, V8 hooks, and shellcode…

binary-exploitationexploitationpayload-development+5
3 months ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubinfenet/cve-2019-0708

Proof-of-concept exploit for CVE-2019-0708 (BlueKeep) targeting Windows RDP, with shellcode for x86 systems. Intended for authorized security testing…

exploitationpayload-developmentpenetration-testing+3
27 years ago
CVE-2025-55182-react2shell preview

CVE-2025-55182-react2shell

GitHubsaturate/cve-2025-55182-react2shell

A bash scanner for detecting CVE-2025-55182 vulnerability in Next.js applications. And a PoC nodejs script

command-and-controlexploitationpayload-development+5
12 months ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubprelearn-code/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

command-and-controlexploitationpayload-development+4
22 years ago
EXPLOIT-CVE-2026-8832- preview

EXPLOIT-CVE-2026-8832-

GitHubfunixone/exploit-cve-2026-8832-

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

code-analysisexploitationpayload-development+5
3 months ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubluoqichen/cve-2025-55182-poc

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

command-and-controlexploitationpayload-development+5
6 months ago
CVE-2022-42475-POC preview

CVE-2022-42475-POC

GitHubarthurhendrich/cve-2022-42475-poc

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

exploitationpayload-developmentpenetration-testing+4
6 months ago
Exploit-CVE-2024-23897 preview

Exploit-CVE-2024-23897

GitHubaadi0258/exploit-cve-2024-23897

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

exploitationpenetration-testingremote-access-tool+3
10 months ago
CVE-2017-7494 preview

CVE-2017-7494

GitHubincredible1yu/cve-2017-7494

C exploit for CVE-2017-7494 (Samba is_known_pipename) with custom shared object compilation and reverse shell payload generation.

binary-exploitationexploitationpayload-development+3
8 years ago
CVE-2021-41773-Apache-2.4.49- preview

CVE-2021-41773-Apache-2.4.49-

GitHubkhaidtraivch/cve-2021-41773-apache-2.4.49-

Exploit scripts for CVE-2021-41773 (Apache 2.4.49) enabling path traversal and remote code execution via CGI, including a reverse shell payload.

exploitationpenetration-testingremote-access-tool+3
1 year ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubyassdev221608/cve-2024-6387

Python exploit for CVE-2024-6387 (OpenSSH signal handler race condition) targeting glibc-based 32-bit Linux systems, with multi-threaded concurrency…

binary-exploitationexploitationpayload-development+3
1 year ago
CVE-2018-4121 preview

CVE-2018-4121

GitHubjezzus/cve-2018-4121

Proof-of-concept remote code execution exploit targeting Safari 11.0.3 on macOS 10.13.3 via a WebAssembly section vulnerability (CVE-2018-4121).…

binary-exploitationexploitationpayload-development+3
8 years ago
baron-samedit preview

baron-samedit

GitHubczeti/baron-samedit

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

binary-exploitationexploitationpayload-development+4
1 year ago
pwn2own2020 preview

pwn2own2020

GitHubsslab-gatech/pwn2own2020

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

binary-exploitationexploitationpayload-development+4
4145 years ago
Chankro preview

Chankro

GitHubtarlogicsecurity/chankro

Herramienta para evadir disable_functions y open_basedir

exploitationpayload-developmentpenetration-testing+3
4957 years ago
drinkme preview

drinkme

GitHubemptymonkey/drinkme

A shellcode testing harness.

exploitationpenetration-testingshellcode
692 years ago
Previous1234…8Next