Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
224 results
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+7
3.9k
2 months ago
wshlient preview

wshlient

GitHubgildasio/wshlient

A simple tool to interact with web shells and command injection vulnerabilities

command-and-controlpenetration-testingshellcode+1
371 year ago
spring-rce-poc preview

spring-rce-poc

GitHubmarcingadz/spring-rce-poc

Testing CVE-2022-22968

exploitationpayload-generationshellcode+2
24 years ago
CVE-2016-3714 preview

CVE-2016-3714

GitHubhood3drob1n/cve-2016-3714

ImaegMagick Code Execution (CVE-2016-3714)

exploitationpayload-developmentpenetration-testing+3
7010 years ago
ASPX_WebShell_COFFLoader preview

ASPX_WebShell_COFFLoader

GitHubepotseluevskaya/aspx_webshell_coffloader

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

command-and-controlpayload-developmentpenetration-testing+3
1375 months ago
CVE-2025-34085-Multi-target preview

CVE-2025-34085-Multi-target

GitHubill-deed/cve-2025-34085-multi-target

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

command-and-controlexploitationpayload-generation+5
341 year ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubjenderal92/cve-2026-48908

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell…

exploitationpayload-generationpenetration-testing+4
31 month ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
21 month ago
WP-Bricks-Exploit-CVE-2024-25600 preview

WP-Bricks-Exploit-CVE-2024-25600

GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

command-and-controlexploitationinformation-gathering+7
11 month ago
r2rs preview

r2rs

GitHubhakkuri01/r2rs

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

command-and-controlexploitationpenetration-testing+3
12 months ago
CVE-2019-16278-Nostromo-1.9.6-RCE preview

CVE-2019-16278-Nostromo-1.9.6-RCE

GitHubcancela24/cve-2019-16278-nostromo-1.9.6-rce

This repository contains an exploit for CVE-2019-16278 in Nostromo Web Server 1.9.6, allowing remote code execution via a directory traversal…

educationexploitationpayload-generation+3
11 year ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubmr-r00t11/cve-2024-23692

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

exploitationpayload-generationpenetration-testing+4
2 years ago
wordpress-exploit-framework preview
Archived

wordpress-exploit-framework

GitHubrastating/wordpress-exploit-framework

A Ruby framework designed to aid in the penetration testing of WordPress systems.

exploit-frameworkspayload-developmentpenetration-testing+3
1.0k6 years ago
CVE-2026-6307 preview

CVE-2026-6307

GitHub0xsha/cve-2026-6307

Google Chrome CVE-2026-6307 PoC

binary-exploitationeducationexploitation+6
531 month ago
CVE-2017-9101 preview

CVE-2017-9101

GitHubjasperla/cve-2017-9101

Exploit for PlaySMS 1.4 authenticated RCE

exploitationpayload-generationpenetration-testing+3
147 years ago
CVE-2025-34085 preview

CVE-2025-34085

GitHubyukinime/cve-2025-34085
exploitationpayload-generationpenetration-testing+3
71 year ago
Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE preview

Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE

GitHubrandallbanner/spring-cloud-function-vulnerability-cve-2022-22963-rce
exploitationpayload-generationpenetration-testing+3
43 years ago
CVE-2020-7115 preview

CVE-2020-7115

GitHubretr02332/cve-2020-7115

Create your malicious engine in seconds

exploitationpayload-generationpenetration-testing+3
15 years ago
Previous12…13Next