Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
228 results
CVE-2024-50379 preview

CVE-2024-50379

GitHubdear-cell/cve-2024-50379

Exploit script for CVE-2024-50379, automating JSP webshell upload and execution via a race condition in Apache Tomcat.

exploitationpayload-generationpenetration-testing+3
1
1 year ago
CVE-2018-2628 preview

CVE-2018-2628

GitHubherantong/cve-2018-2628

Python-based exploit for CVE-2018-2628 targeting Oracle WebLogic Server, providing vulnerability detection and remote shell access via JSP payload…

exploitationpayload-generationpenetration-testing+3
19 months ago
CVE-2024-23738 preview

CVE-2024-23738

GitHubgiovannipajeu1/cve-2024-23738

Proof-of-concept exploit for CVE-2024-23738 targeting Postman on macOS. Automates vulnerability detection and code injection via Electron settings to…

exploitationpayload-generationremote-access-tool+3
12 years ago
CVE-2019-16278-Nostromo-1.9.6-RCE preview

CVE-2019-16278-Nostromo-1.9.6-RCE

GitHubcancela24/cve-2019-16278-nostromo-1.9.6-rce

Exploit for CVE-2019-16278 targeting Nostromo Web Server 1.9.6, achieving remote code execution via directory traversal. Uses pwntools to deliver a…

educationexploitationpayload-generation+3
11 year ago
CVE-2024-23742 preview

CVE-2024-23742

GitHubgiovannipajeu1/cve-2024-23742

Proof-of-concept exploit for CVE-2024-23742 in Loom for macOS. Validates vulnerability and injects arbitrary code via RunAsNode settings to gain a…

exploitationpayload-generationpenetration-testing+3
12 years ago
CVE-2024-23743 preview

CVE-2024-23743

GitHubgiovannipajeu1/cve-2024-23743

Automated exploit tool for CVE-2024-23743 targeting Notion macOS via RunAsNode and enableNodeClilnspectArguments, enabling remote code execution and…

exploitationpayload-generationshellcode+2
12 years ago
CVE-2021-21220 preview

CVE-2021-21220

GitHubjacobtaylor3/cve-2021-21220

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.

command-and-controlexploitationlateral-movement+5
6 months ago
CVE-2025-6002 preview

CVE-2025-6002

GitHubschn1tzelme1ster/cve-2025-6002

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

exploitationpayload-generationpenetration-testing+3
6 months ago
exploit_CVE-2024-39205 preview

exploit_CVE-2024-39205

GitHubbtar1gan/exploit_cve-2024-39205

Exploit for CVE-2024-39205, a js2py sandbox escape that enables remote code execution and establishes a reverse shell.

exploitationpayload-generationpenetration-testing+3
19 months ago
Exploit-CVE-2024-23897 preview

Exploit-CVE-2024-23897

GitHubaadi0258/exploit-cve-2024-23897

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

exploitationpenetration-testingremote-access-tool+3
11 months ago
Rig-Exploit-for-CVE-2018-8174 preview

Rig-Exploit-for-CVE-2018-8174

GitHuborf53975/rig-exploit-for-cve-2018-8174

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

command-and-controlexploitationmalware-analysis+3
8 years ago
cve-2023-3824 preview

cve-2023-3824

GitHubdadosneurais/cve-2023-3824

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

command-and-controlexploitationpayload-generation+3
1 year ago
CVE-2022-41544 preview

CVE-2022-41544

GitHubh3x0v3rl0rd/cve-2022-41544

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2021-41773-Apache-2.4.49- preview

CVE-2021-41773-Apache-2.4.49-

GitHubkhaidtraivch/cve-2021-41773-apache-2.4.49-

Exploit scripts for CVE-2021-41773 (Apache 2.4.49) enabling path traversal and remote code execution via CGI, including a reverse shell payload.

exploitationpenetration-testingremote-access-tool+3
1 year ago
CVE-2019-0232_tomcat_cgi_exploit preview

CVE-2019-0232_tomcat_cgi_exploit

GitHubx3m1sec/cve-2019-0232_tomcat_cgi_exploit

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

educationexploitationpayload-generation+3
1 year ago
bludit-CVE-2019-17240 preview

bludit-CVE-2019-17240

GitHubjayngng/bludit-cve-2019-17240

Bypass bludit mitigation login form and upload malicious to call a rev shell

authentication-authorizationexploitationpayload-generation+2
5 years ago
CVE-2020-24186 preview

CVE-2020-24186

GitHubgazettel/cve-2020-24186

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…

exploitationpayload-generationpenetration-testing+4
1 year ago
CVE-2018-4121 preview

CVE-2018-4121

GitHubjezzus/cve-2018-4121

Proof-of-concept remote code execution exploit targeting Safari 11.0.3 on macOS 10.13.3 via a WebAssembly section vulnerability (CVE-2018-4121).…

binary-exploitationexploitationpayload-development+3
8 years ago
Previous1…456…13Next