Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3598 results
CVE-2022-39197 preview

CVE-2022-39197

GitHubits-arun/cve-2022-39197

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

command-and-controlexploitationpayload-development+3
387
3 years ago
POC-CVE-2025-24813 preview

POC-CVE-2025-24813

GitHubabsholi7ly/poc-cve-2025-24813

his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in…

exploitationpayload-developmentpenetration-testing+3
1971 year ago
CVE-2016-0051 preview

CVE-2016-0051

GitHubhexx0r/cve-2016-0051

Proof-of-concept exploit for CVE-2016-0051 (MS16-016) achieving local privilege escalation to SYSTEM on Windows 7, with compiled binaries and…

binary-exploitationexploitationpayload-development+2
4110 years ago
CVE-2024-4577-RCE preview

CVE-2024-4577-RCE

GitHubgh-ost00/cve-2024-4577-rce

Exploit for PHP CGI Argument Injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers running Apache and PHP-CGI.…

exploitationpayload-developmentpenetration-testing+3
252 years ago
CVE-2018-3245 preview

CVE-2018-3245

GitHubjas502n/cve-2018-3245

Exploit for CVE-2018-3245, a Weblogic remote code execution vulnerability, with a provided payload to obtain a reverse shell.

exploitationpayload-developmentpenetration-testing+2
147 years ago
CVE-2017-17562 preview

CVE-2017-17562

GitHubivanitlearning/cve-2017-17562

Standalone Python 3 exploit for CVE-2017-17562 targeting GoAhead web server 2.5–3.6.5 with automated CGI endpoint discovery and reverse shell payload…

exploitationpayload-developmentpenetration-testing+3
106 years ago
cve-2023-42115 preview

cve-2023-42115

GitHubkirinse/cve-2023-42115

Python-based exploit and reverse shell payload generator for CVE-2023-42115, featuring scan and exploit modes with cross-platform payload creation.

exploitationpayload-developmentpayload-generation+3
92 years ago
exch_CVE-2021-42321 preview

exch_CVE-2021-42321

GitHub7bitsteam/exch_cve-2021-42321

Modified .NET deserialization payload for CVE-2021-42321, based on ysoserial.net, that writes files and bypasses Windows Defender to target Microsoft…

binary-exploitationexploitationpayload-development+3
103 years ago
CVE-2019-18935-bypasswaf preview

CVE-2019-18935-bypasswaf

GitHubekkoo-z/cve-2019-18935-bypasswaf

Exploit for CVE-2019-18935 (Telerik UI) with WAF bypass via encrypted cookie payload injection and custom memory shell deployment.

exploitationpayload-developmentpenetration-testing+3
81 year ago
CVE-2022-21445-for-12.2.1.3.0-Weblogic preview

CVE-2022-21445-for-12.2.1.3.0-Weblogic

GitHubhienkiet/cve-2022-21445-for-12.2.1.3.0-weblogic

Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup,…

code-analysisexploitationpayload-development+4
52 years ago
CVE-2020-9047 preview

CVE-2020-9047

GitHubnorrismw/cve-2020-9047

Python exploit for CVE-2020-9047 targeting exacqVision Web Service. Supports Windows/Linux payload delivery, remote command execution, and…

exploitationpayload-developmentpenetration-testing+3
116 years ago
MouseServer-1.7.8.5-RCE preview

MouseServer-1.7.8.5-RCE

GitHubmermehr/mouseserver-1.7.8.5-rce

PoC exploit for CVE-2022-3218 targeting WiFi Mouse Server 1.7.8.5, achieving RCE via keystroke injection and in-memory PowerShell payload delivery…

exploitationpayload-developmentpenetration-testing+2
10 days ago
CVE-2026-0920 preview

CVE-2026-0920

GitHubjohn-doe-code-a11/cve-2026-0920

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

exploitationpayload-developmentpenetration-testing+2
77 months ago
Exploit-For-CVE-2022-36067 preview

Exploit-For-CVE-2022-36067

GitHubprathamhasnotchanged/exploit-for-cve-2022-36067

This repo contains payload for the CVE-2022-36067

exploitationpayload-developmentpenetration-testing+2
73 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubmaximofernandezriera/cve-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

exploitationpayload-developmentpenetration-testing+2
54 years ago
CVE-2022-21350 preview

CVE-2022-21350

GitHubhktalent/cve-2022-21350

Exploit toolkit for CVE-2022-21350 targeting Oracle WebLogic T3 protocol with payload generation, LDAP/HTTP servers, and support for multiple JDK…

command-and-controlexploitationpayload-development+3
32 years ago
CVE-2019-16113 preview

CVE-2019-16113

GitHubynots0ups/cve-2019-16113

Python proof-of-concept exploit for Bludit 3.9.2 remote code execution via directory traversal in image upload, enabling PHP payload injection to…

exploitationpayload-developmentpenetration-testing+2
56 years ago
CVE-2020-25042-PoC preview

CVE-2020-25042-PoC

GitHubgroppoxx/cve-2020-25042-poc

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

exploitationpayload-developmentpenetration-testing+3
53 months ago
Previous12…100Next