Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
469 results
CVE-2025-32433-PoC preview

CVE-2025-32433-PoC

GitHubniteeshpujari/cve-2025-32433-poc

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

ctfeducationexploitation+3
7
1 year ago
CVE-2026-29782-OpenSTAManager-RCE preview

CVE-2026-29782-OpenSTAManager-RCE

GitHubhackerking24/cve-2026-29782-openstamanager-rce

Proof-of-concept exploit for CVE-2026-29782, chaining SQL injection and PHP object injection to achieve remote code execution in OpenSTAManager.…

ctfeducationexploitation+2
17 days ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

ctfeducationexploitation+5
63 months ago
CVE-2023-33733-Exploit-PoC preview

CVE-2023-33733-Exploit-PoC

GitHubl41kaa/cve-2023-33733-exploit-poc

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

ctfexploitationpayload-generation+3
32 years ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubr4y-br/cve-2022-22963

Python automation script that reproduces CVE-2022-22963, a critical SpEL injection in Spring Cloud Function, enabling reverse shell in authorized lab…

ctfeducationexploitation+3
1 month ago
CVE-2024-3829 preview

CVE-2024-3829

GitHubfabse-hack/cve-2024-3829

Python exploit for CVE-2024-3829 targeting Qdrant snapshot import/export, enabling file read, file write, and reverse shell execution via symlink…

ctfexploitationpayload-development+3
12 months ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubhklabcr/cve-2011-2523

Manual and automated exploitation walkthrough for vsftpd 2.3.4 backdoor (CVE-2011-2523) with custom reverse shell payload and Metasploit integration…

ctfeducationexploitation+5
1 year ago
CVE-2024-31317-Deployer preview

CVE-2024-31317-Deployer

GitHubkalibb/cve-2024-31317-deployer

Automated deployment tool for CVE-2024-31317, a command injection vulnerability in Android 9-13. Includes reverse shell payload, compile script, and…

android-securitybinary-exploitationcommand-and-control+5
7 months ago
CVE-2019-12735 preview

CVE-2019-12735

GitHubdatntsec/cve-2019-12735

Detailed technical analysis and proof-of-concept for CVE-2019-12735, an arbitrary code execution vulnerability in Vim/Neovim via modeline sandbox…

binary-exploitationctfeducation+3
5 years ago
CVE-2015-1397-Magento-Shoplift preview

CVE-2015-1397-Magento-Shoplift

GitHubwytchwulf/cve-2015-1397-magento-shoplift

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

ctfexploitationpayload-generation+3
2 years ago
CVE-2025-22457-vulnserver-lab preview

CVE-2025-22457-vulnserver-lab

GitHubdonofly/cve-2025-22457-vulnserver-lab

Hands-on lab reproducing CVE-2025-22457: sets up Docker attacker/victim containers, finds stack addresses with GDB, and delivers a msfvenom reverse…

binary-exploitationctfeducation+6
2 days ago
CVE-2022-39952 preview

CVE-2022-39952

GitHubhorizon3ai/cve-2022-39952

Proof-of-concept exploit for CVE-2022-39952 targeting Fortinet FortiNAC. Abuses keyUpload.jsp endpoint for arbitrary file write to deploy cron-based…

exploitationpayload-developmentpenetration-testing+3
2653 years ago
through_the_wire preview

through_the_wire

GitHubjbaines-r7/through_the_wire

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

command-and-controlexploitationpayload-generation+3
1734 years ago
Webmin-CVE-2022-0824-revshell preview

Webmin-CVE-2022-0824-revshell

GitHubfaisalfs10x/webmin-cve-2022-0824-revshell

Post-authentication reverse shell exploit for Webmin <=1.984 leveraging CVE-2022-0824 File Manager privilege escalation. Downloads and executes a CGI…

exploitationpayload-generationpenetration-testing+3
1134 years ago
logrotten preview

logrotten

GitHubwhotwagner/logrotten

Logrotate race condition exploit that enables privilege escalation by writing arbitrary files, such as reverse shell payloads, into system…

binary-exploitationexploitationpenetration-testing+4
2168 months ago
CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ preview

CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ

GitHubsaumyajeetdas/cve-2023-46604-rce-reverse-shell-apache-activemq

Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)

command-and-controlexploitationpayload-generation+3
1262 years ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
Previous12…27Next