Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1225 results
CVE-2026-58457 preview

CVE-2026-58457

GitHubj4ck3lsyn-gen2/cve-2026-58457

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

command-and-controleducationexploitation+7
2
2 months ago
CVE-2019-7304_DirtySock preview

CVE-2019-7304_DirtySock

GitHubsecuritysi/cve-2019-7304_dirtysock

Payload Generator

exploitationpayload-generationpenetration-testing+2
67 years ago
CVE-2022-44149 preview

CVE-2022-44149

GitHubgeniuszly/cve-2022-44149

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

exploitationpayload-generationpenetration-testing+3
52 years ago
CVE-2023-38831-winrar-exploit preview

CVE-2023-38831-winrar-exploit

GitHubb1tg/cve-2023-38831-winrar-exploit

CVE-2023-38831 winrar exploit generator

exploitationpayload-generationpenetration-testing+3
7832 years ago
ysonet preview

ysonet

GitHubirsdl/ysonet

Deserialization payload generator for a variety of .NET formatters

exploitationpayload-generationpenetration-testing+3
24010 days ago
Apache-Struts-v4 preview

Apache-Struts-v4

GitHubs1kr10s/apache-struts-v4

Exploit script targeting 5 Apache Struts RCE vulnerabilities (CVE-2013-2251, CVE-2017-5638, CVE-2017-9805, CVE-2018-11776, CVE-2019-0230) with PHP…

exploitationpayload-generationvulnerability-analysis+1
2055 years ago
Webmin-CVE-2022-0824-revshell preview

Webmin-CVE-2022-0824-revshell

GitHubfaisalfs10x/webmin-cve-2022-0824-revshell

Post-authentication reverse shell exploit for Webmin <=1.984 leveraging CVE-2022-0824 File Manager privilege escalation. Downloads and executes a CGI…

exploitationpayload-generationpenetration-testing+3
1124 years ago
ppsx-file-generator preview

ppsx-file-generator

GitHubtemesgeny/ppsx-file-generator

ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)

exploitationpayload-generationpenetration-testing+3
668 years ago
CVE-2020-17530 preview

CVE-2020-17530

GitHubka1n4t/cve-2020-17530

Proof-of-concept exploit for CVE-2020-17530 (Apache Struts2 S2-061) with OGNL injection payload for remote code execution testing.

exploitationpayload-generationpenetration-testing+2
645 years ago
watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882 preview

watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

GitHubwatchtowrlabs/watchtowr-vs-oracle-e-business-suite-cve-2025-61882

Generates detection artifacts for Oracle E-Business Suite CVE-2025-61882 by serving a reverse shell payload to verify pre-auth RCE.

exploitationpayload-generationpenetration-testing+3
551 year ago
CVE-2022-40146_Exploit_Jar preview

CVE-2022-40146_Exploit_Jar

GitHubcckuailong/cve-2022-40146_exploit_jar

Java-based exploit for Apache Batik SSRF to RCE (CVE-2022-40146) with payload generation via jar and ecmascript, enabling remote class loading…

exploitationpayload-generationpenetration-testing+3
313 years ago
ACEDcup preview

ACEDcup

GitHubgrrrdog/acedcup

Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)

exploitationpayload-generationpenetration-testing+2
3710 years ago
CVE-2015-6967 preview

CVE-2015-6967

GitHubdix0nym/cve-2015-6967

Python exploit script for CVE-2015-6967, enabling authenticated arbitrary file upload in Nibbleblog 4.0.3 with custom payload support.

exploitationpayload-generationpenetration-testing+2
155 years ago
CVE-2025-59287-WSUS preview

CVE-2025-59287-WSUS

GitHubtecxx/cve-2025-59287-wsus

PowerShell proof-of-concept exploit for CVE-2025-59287 targeting WSUS servers. Automates payload generation with ysoserial.net and triggers a reverse…

exploitationpayload-generationpenetration-testing+3
1811 months ago
CVE-2019-16113 preview

CVE-2019-16113

GitHubcybervaca/cve-2019-16113

Python exploit script for CVE-2019-16113, an authenticated remote code execution vulnerability in Bludit CMS 3.9.2+, with reverse shell payload…

exploitationpayload-generationpenetration-testing+3
136 years ago
CVE-2018-15982_EXP_IE preview

CVE-2018-15982_EXP_IE

GitHubjas502n/cve-2018-15982_exp_ie

Exploit generator for CVE-2018-15982 (Adobe Flash Player) that produces SWF and HTML files for remote code execution via crafted Flash objects.

exploitationpayload-generationpenetration-testing+2
127 years ago
CVE-2017-12149 preview

CVE-2017-12149

GitHubjreppiks/cve-2017-12149

Python script exploiting JBoss Java deserialization RCE (CVE-2017-12149) using ysoserial for dynamic payload generation. Requires Java runtime.

exploitationpayload-generationpenetration-testing+2
147 years ago
CVE-2024-21006_jar preview

CVE-2024-21006_jar

GitHublightr3d/cve-2024-21006_jar

Java-based exploit for CVE-2024-21006, delivering a payload via LDAP to a target IP and port. Includes compiled JAR and source for customization.

exploitationpayload-generationpenetration-testing+2
162 years ago
Previous12…69Next