Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
CSSG preview

CSSG

GitHubrcstep/cssg

Cobalt Strike aggressor script for generating, formatting, and encrypting beacon shellcode with support for multiple exit methods, syscalls, and…

encryption-decryption-toolsexploit-frameworkspayload-generation+2
666
2 years ago
CVE-2022-41343 preview

CVE-2022-41343

GitHubbkreisel/cve-2022-41343

🐍 Python Exploit for CVE-2022-23935

exploitationpayload-generationpenetration-testing+3
33 years ago
CVE-2022-46169 preview

CVE-2022-46169

GitHubbkreisel/cve-2022-46169

🐍 Python Exploit for CVE-2022-46169

exploitationpayload-generationpenetration-testing+3
3 years ago
EXCELntDonut preview

EXCELntDonut

GitHubredsiege/excelntdonut

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

exploitationpayload-generationphishing+4
5166 years ago
CVE-2020-5844 preview

CVE-2020-5844

GitHubthecybergeek/cve-2020-5844

Python proof-of-concept for authenticated remote code execution in PandoraFMS 7.0-NG 742, enabling admin users to upload malicious PHP and obtain a…

exploitationpayload-generationpenetration-testing+3
45 years ago
noSAMBAnoCRY-CVE-2017-7494 preview

noSAMBAnoCRY-CVE-2017-7494

GitHub0xm4ud/nosambanocry-cve-2017-7494

CVE-2017-7494 python exploit

exploitationpayload-generationpenetration-testing+3
65 years ago
CVE-2018-12613 preview

CVE-2018-12613

GitHubivanitlearning/cve-2018-12613

Modified standalone exploit ported for Python 3

exploitationpayload-generationpenetration-testing+3
47 years ago
Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE preview

Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE

GitHubrandallbanner/spring-cloud-function-vulnerability-cve-2022-22963-rce

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

exploitationpayload-generationpenetration-testing+3
43 years ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubcowsecurity/cve-2011-2523

Python exploit for vsFTPd backdoor vulnerability (CVE-2011-2523) using Pwntools for remote code execution against target IP and port.

exploitationpayload-generationpenetration-testing+3
23 years ago
CVE-2020-8644-PlaySMS-1.4 preview

CVE-2020-8644-PlaySMS-1.4

GitHubh3rm1tr3b0rn/cve-2020-8644-playsms-1.4

Python script to exploit PlaySMS before 1.4.3

exploitationpayload-generationpenetration-testing+3
23 years ago
CVE-2025-6002 preview

CVE-2025-6002

GitHubschn1tzelme1ster/cve-2025-6002

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

exploitationpayload-generationpenetration-testing+3
6 months ago
CVE-2007-2447 preview

CVE-2007-2447

GitHub3x1t1um/cve-2007-2447

Python exploit for CVE-2007-2447 that triggers Samba username map script command injection to open a reverse shell on vulnerable targets.

exploitationpayload-generationpenetration-testing+3
16 years ago
WordPress-HT-Contact-CVE-2025-7340-RCE preview

WordPress-HT-Contact-CVE-2025-7340-RCE

GitHubkai-one001/wordpress-ht-contact-cve-2025-7340-rce

Python exploit for CVE-2025-7340, an unauthenticated file upload vulnerability in the WordPress HT Contact Form widget, enabling remote code…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2022-41544 preview

CVE-2022-41544

GitHubh3x0v3rl0rd/cve-2022-41544

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

exploitationpayload-generationpenetration-testing+3
1 year ago
SpringFramework_CVE-2022-22965_RCE preview

SpringFramework_CVE-2022-22965_RCE

GitHubxsxtw/springframework_cve-2022-22965_rce

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

exploitationpayload-generationpenetration-testing+3
4 years ago
CVE-2019-11447_reverse_shell_upload preview

CVE-2019-11447_reverse_shell_upload

GitHubsubsting/cve-2019-11447_reverse_shell_upload

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

exploitationpayload-generationpenetration-testing+3
2 years ago
cve-2022-29464 preview

cve-2022-29464

GitHublowkey0808/cve-2022-29464

Python exploit for CVE-2022-29464 targeting WSO2 web servers with automated webshell upload and command execution capabilities.

exploitationpayload-generationpenetration-testing+3
4 years ago
chamilo-lms-unauthenticated-rce-poc preview

chamilo-lms-unauthenticated-rce-poc

GitHubcharchit-subedi/chamilo-lms-unauthenticated-rce-poc

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

exploitationpayload-generationpenetration-testing+3
2 years ago
Previous123Next