Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
884 results
CVE-2021-4034 preview

CVE-2021-4034

GitHubmebeim/cve-2021-4034

Proof-of-concept exploit for CVE-2021-4034, a local privilege escalation in polkit's pkexec, demonstrating exploitation with simple C helpers and a…

exploitationexploit-frameworkspenetration-testing+2
36
4 years ago
SMBGhost-LPE-Metasploit-Module preview

SMBGhost-LPE-Metasploit-Module

GitHubalmorabea/smbghost-lpe-metasploit-module

This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework

exploitationexploit-frameworkspenetration-testing+2
206 years ago
CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit preview

CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit

GitHubakucybersec/cve-2022-1329-wordpress-elementor-3.6.0-3.6.1-3.6.2-remote-code-execution-exploit

Exploit for CVE-2022-1329, a WordPress Elementor plugin RCE vulnerability, allowing authenticated users to upload and execute arbitrary PHP files via…

exploit-frameworkspayload-developmentpenetration-testing+3
234 years ago
CVE-2021-21972 preview

CVE-2021-21972

GitHubtaroballzchen/cve-2021-21972

CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script

exploitationexploit-frameworkspayload-development+3
195 years ago
weblogic-cve-2018-2628 preview

weblogic-cve-2018-2628

GitHubjiansiting/weblogic-cve-2018-2628

Python exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability. Provides remote code execution against unpatched…

exploitationexploit-frameworkspenetration-testing+2
148 years ago
cve-2021-1675 preview

cve-2021-1675

GitHubk8gege/cve-2021-1675

Exploit for CVE-2021-1675 (PrintNightmare) enabling local and remote SYSTEM-level privilege escalation on Windows via the Print Spooler service.…

exploitationexploit-frameworkspenetration-testing+2
155 years ago
CVE-2018-3252 preview

CVE-2018-3252

GitHubgo-spider/cve-2018-3252

Exploit for CVE-2018-3252 targeting WebLogic deserialization vulnerability. Includes payload generation with ysoserial and a Python proof-of-concept…

binary-exploitationexploit-frameworkspayload-development+3
187 years ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubwqsemc/cve-2019-0708

initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly…

exploitationexploit-frameworkspayload-development+3
127 years ago
annotated-fbi-tbb-exploit preview

annotated-fbi-tbb-exploit

GitHubvlad902/annotated-fbi-tbb-exploit

Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)

exploitationexploit-frameworksvulnerability-analysis+1
1512 years ago
unrar-cve-2022-30333-poc preview

unrar-cve-2022-30333-poc

GitHubrbowes-r7/unrar-cve-2022-30333-poc

Proof-of-concept exploit for CVE-2022-30333 path traversal in unRAR, generating malicious .rar files to plant payloads at arbitrary locations.…

exploitationexploit-frameworkspayload-generation+3
144 years ago
CVE-2019-0708-EXP-MSF- preview

CVE-2019-0708-EXP-MSF-

GitHubqing-root/cve-2019-0708-exp-msf-

CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708

exploitationexploit-frameworkspenetration-testing+3
117 years ago
CVE-2017-7269 preview

CVE-2017-7269

GitHubal1ex/cve-2017-7269

Exploit for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution. Designed for use with Metasploit in penetration…

exploit-frameworkspenetration-testingremote-access-tool+2
118 years ago
Pack2TheRoot preview

Pack2TheRoot

GitHubshibaaa204/pack2theroot

Proof-of-concept exploit for CVE-2026-41651, a Linux local privilege escalation vulnerability in Pack2 software, demonstrating root access and system…

exploitationexploit-frameworkspenetration-testing+2
94 months ago
CVE-2021-24155.rb preview

CVE-2021-24155.rb

GitHub0dayninja/cve-2021-24155.rb

WordPress Backup Guard Authenticated Remote Code Execution Exploit

exploit-frameworkspayload-developmentpenetration-testing+3
105 years ago
cobaltstrike_swing_xss2rce preview

cobaltstrike_swing_xss2rce

GitHubhluwa/cobaltstrike_swing_xss2rce

Exploit for CVE-2022-39197, a cross-site scripting vulnerability in Cobalt Strike's Swing GUI that enables remote code execution on team servers.

command-and-controlexploit-frameworkspenetration-testing+3
73 years ago
CVE-2019-15029 preview

CVE-2019-15029

GitHubmhaskar/cve-2019-15029

The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029

exploitationexploit-frameworkspenetration-testing+3
86 years ago
Wazuh-RCE preview

Wazuh-RCE

GitHubguinea-offensive-security/wazuh-rce

Remote code execution exploit for Wazuh 8.4 (CVE-2025-24016) with Python-based proof-of-concept targeting vulnerable SIEM deployments.

exploitationexploit-frameworkspenetration-testing+2
81 year ago
THERE-IS-A-CVE preview

THERE-IS-A-CVE

GitHubransomwares/there-is-a-cve

Pentesting tool integrating Shodan for IP reconnaissance and CVE identification, with Metasploit and Exploit-DB integration for automated exploit…

exploit-frameworksinformation-gatheringpenetration-testing+1
122 years ago
Previous1234…50Next