Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
93 results
nmap-log4shell preview

nmap-log4shell

GitHubgiterlizzi/nmap-log4shell

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

exploitationnetwork-securitypayload-generation+4
79
4 years ago
masta-cve-2026-48907 preview

masta-cve-2026-48907

GitHubgh1mau/masta-cve-2026-48907

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

exploitationpayload-generationpenetration-testing+4
571 month ago
watchTowr-vs-FortiWeb-CVE-2025-25257 preview

watchTowr-vs-FortiWeb-CVE-2025-25257

GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

Detection artifact generator for FortiWeb CVE-2025-25257, exploiting unauthenticated SQL injection to achieve remote code execution via hex-encoded…

exploitationpayload-generationpenetration-testing+3
1001 year ago
Log4j-check preview

Log4j-check

GitHubbigsizeme/log4j-check

log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload

dns-analysisexploitationpayload-generation+3
704 years ago
CVE-2024-25600_Nuclei-Template preview

CVE-2024-25600_Nuclei-Template

GitHubchristbowel/cve-2024-25600_nuclei-template

Nuclei template and information about the POC for CVE-2024-25600

exploitationpayload-generationpenetration-testing+3
312 years ago
watchTowr-vs-FreePBX-CVE-2025-57819 preview

watchTowr-vs-FreePBX-CVE-2025-57819

GitHubwatchtowrlabs/watchtowr-vs-freepbx-cve-2025-57819

Python-based detection artifact generator for CVE-2025-57819, exploiting FreePBX pre-auth RCE via SQL injection and auth bypass to deploy webshells…

exploitationpayload-generationpenetration-testing+3
2811 months ago
php-cgi-Injector preview

php-cgi-Injector

GitHubnight-have-dreams/php-cgi-injector

Automated PHP-CGI parameter injection exploit tool targeting CVE-2024-4577 and CVE-2024-8926. Supports command execution, file upload/download, WAF…

command-and-controlexploitationpayload-generation+4
521 year ago
CVE-2025-34085-Multi-target preview

CVE-2025-34085-Multi-target

GitHubill-deed/cve-2025-34085-multi-target

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

command-and-controlexploitationpayload-generation+5
351 year ago
vbulletin5-rce preview

vbulletin5-rce

GitHubthelsa/vbulletin5-rce

CVE-2019-16759 vbulletin 5.0.0 till 5.5.4 pre-auth rce

exploitationpayload-generationpenetration-testing+2
206 years ago
Next.js-RCE-Scanner-BurpSuite-Extension- preview

Next.js-RCE-Scanner-BurpSuite-Extension-

GitHubcr4at0r/next.js-rce-scanner-burpsuite-extension-

Burp Suite extension for automated detection and exploitation of CVE-2025-55182 Next.js RCE vulnerability with echo/DNSLog checks and memory shell…

command-and-controlexploitationpayload-generation+3
268 months ago
hideNsneak preview

hideNsneak

GitHubrmikehodges/hidensneak

CLI for rapidly deploying, managing, and tearing down ephemeral cloud-based penetration testing infrastructure, including VMs, C2 servers, domain…

cloud-securitycommand-and-controlpayload-generation+5
176 years ago
vcenter_rce preview

vcenter_rce

GitHubma1dong/vcenter_rce

漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell

exploitationpayload-generationpenetration-testing+3
115 years ago
CVE-2025-55315-PoC-Exploit preview

CVE-2025-55315-PoC-Exploit

GitHubzemarkhos/cve-2025-55315-poc-exploit

Exploitation tool for CVE-2025-55315, an HTTP request smuggling vulnerability in ASP.NET Core Kestrel. Detects vulnerable endpoints, extracts…

exploitationpayload-generationpenetration-testing+3
99 months ago
Automated-blind-xss-search-for-Burp-Suite preview

Automated-blind-xss-search-for-Burp-Suite

GitHubianxtianxt/automated-blind-xss-search-for-burp-suite

Burp Suite plugin for automated blind XSS detection with active and passive scanning, customizable OOB payloads, and configurable parameters for…

payload-generationpenetration-testingvulnerability-scanners+2
96 years ago
CVE-2025-55182-React2shell preview

CVE-2025-55182-React2shell

GitHubjenderal92/cve-2025-55182-react2shell

CVE-2025-55182 Exploit Tool – Python 2.7 exploit for Next.js prototype pollution leading to RCE

exploitationpayload-generationpenetration-testing+3
62 months ago
CVE-2021-42013-Apache-RCE-Poc-Exp preview

CVE-2021-42013-Apache-RCE-Poc-Exp

GitHubasaotomo/cve-2021-42013-apache-rce-poc-exp

Batch detection and exploitation tool for Apache HTTP Server path traversal and RCE (CVE-2021-42013), with POC and EXP payloads for security testing.

exploitationpayload-generationpenetration-testing+3
104 years ago
ActiveMQ-cve-2026-42588-scanner-gui preview

ActiveMQ-cve-2026-42588-scanner-gui

GitHubstrivepan/activemq-cve-2026-42588-scanner-gui

GUI-based scanner and exploit tool for CVE-2026-42588 (ActiveMQ RCE). Supports VPS payload delivery and DNSLog-based vulnerability verification with…

command-and-controlexploitationpayload-generation+3
102 months ago
G0BurpSQLmaPI preview

G0BurpSQLmaPI

GitHubnu11secur1ty/g0burpsqlmapi

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

exploitationpayload-generationpenetration-testing+2
31 month ago
Previous123456Next