Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
0-click-RCE-Exploit-for-CVE-2024-50526 preview

0-click-RCE-Exploit-for-CVE-2024-50526

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50526

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

exploitationpayload-generationpenetration-testing+5
3
7 months ago
CVE-2025-48827 preview

CVE-2025-48827

GitHubwiseep/cve-2025-48827

Vbullettin RCE - CVE-2025-48827

exploitationpayload-generationpenetration-testing+3
1 year ago
0-click-RCE-Exploit-for-CVE-2024-50498 preview

0-click-RCE-Exploit-for-CVE-2024-50498

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50498

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

exploitationpayload-generationpenetration-testing+5
17 months ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
DAws preview

DAws

GitHubdotcppfile/daws

Advanced Web Shell

ids-ips-evasionpayload-generationpenetration-testing+6
5809 years ago
CVE-2024-51793 preview

CVE-2024-51793

GitHubktn1990/cve-2024-51793

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

code-analysisexploitationpayload-generation+6
18 months ago
nano preview

nano

GitHubs0md3v/nano

Nano is a family of PHP web shells which are code golfed for stealth.

command-and-controlpayload-generationpenetration-testing+3
4496 years ago
b4tm4n preview

b4tm4n

GitHubk4mpr3t/b4tm4n

B4TM4N ~ PHP WEBSHELL

payload-generationremote-access-toolshellcode+1
1887 years ago
pinky preview

pinky

GitHubdavidtavarez/pinky

pinky - The PHP mini RAT (Remote Administration Tool)

command-and-controlencryption-decryption-toolspayload-generation+6
767 years ago
TimeAfterFree preview

TimeAfterFree

GitHubm0x41nos/timeafterfree

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

binary-exploitationeducationexploitation+3
966 months ago
CVE-2025-34085-Multi-target preview

CVE-2025-34085-Multi-target

GitHubill-deed/cve-2025-34085-multi-target

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

command-and-controlexploitationpayload-generation+5
341 year ago
CVE-2020-5844 preview

CVE-2020-5844

GitHubthecybergeek/cve-2020-5844

Python proof-of-concept for authenticated remote code execution in PandoraFMS 7.0-NG 742, enabling admin users to upload malicious PHP and obtain a…

exploitationpayload-generationpenetration-testing+3
45 years ago
CVE-2023-41425-RCE-WonderCMS-4.3.2 preview

CVE-2023-41425-RCE-WonderCMS-4.3.2

GitHubtea-on/cve-2023-41425-rce-wondercms-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

educationexploitationpayload-generation+5
81 year ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
21 month ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubwearehackers160/cve-2026-48907

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

exploitationpayload-generationpenetration-testing+3
2 months ago
CVE-2025-6002 preview

CVE-2025-6002

GitHubschn1tzelme1ster/cve-2025-6002

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

exploitationpayload-generationpenetration-testing+3
5 months ago
EXPLOIT-CVE-2026-8832- preview

EXPLOIT-CVE-2026-8832-

GitHubfunixone/exploit-cve-2026-8832-

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

code-analysisexploitationpayload-development+5
3 months ago
CVE-2023-3519 preview

CVE-2023-3519

GitHubpasswa11/cve-2023-3519

Python exploit for CVE-2023-3519 targeting Citrix ADC with custom NASM shellcode, PHP backdoor deployment, and SUID privilege escalation.

exploitationpayload-developmentremote-access-tool+3
13 years ago
Previous12Next