Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
228 results
CVE-2025-31324-File-Upload preview

CVE-2025-31324-File-Upload

GitHubnullcult/cve-2025-31324-file-upload

A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.

exploitationpenetration-testingred-teaming+2
2
1 year ago
CVE-2026-27966--RCE-in-Langflow preview

CVE-2026-27966--RCE-in-Langflow

GitHubanon-cyber-team/cve-2026-27966--rce-in-langflow

All-in-one exploit tool for CVE-2026-27966, a critical RCE in Langflow. Features mass scanning, auto-detection, payload execution, interactive shell,…

command-and-controlexploitationpenetration-testing+3
26 months ago
watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260 preview

watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260

GitHubwatchtowrlabs/watchtowr-vs-bmc-footprints-rce-cve-2025-71257-cve-2025-71260

Detection artifact generator that verifies BMC FootPrints instances for pre-authenticated RCE chain (CVE-2025-71257, CVE-2025-71260) by bypassing…

authenticationexploitationpenetration-testing+3
26 months ago
CVE-2024-24919-Exploit-PoC-Checkpoint-Firewall-VPN preview

CVE-2024-24919-Exploit-PoC-Checkpoint-Firewall-VPN

GitHubr4p3c4/cve-2024-24919-exploit-poc-checkpoint-firewall-vpn

Herramienta de explotación para explotar la vulnerabilidad CVE-2024-24919 en las VPN de Checkpoint Firewall

exploitationpenetration-testingred-teaming+3
22 years ago
Abyssal preview

Abyssal

GitHubstoerti2/abyssal

Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061, delivering root shells on vulnerable systems with false-positive…

exploitationnetwork-securitypenetration-testing+3
2 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubim-hanzou/cve-2026-3844

Breeze Cache WordPress <=2.4.4 allows unauthenticated file upload via fetch_gravatar_from_remote when local gravatar hosting is enabled.

exploitationpenetration-testingred-teaming+2
4 months ago
cPanel-WHM-CVE-2026-41940-AuthBypass preview

cPanel-WHM-CVE-2026-41940-AuthBypass

GitHubisee857/cpanel-whm-cve-2026-41940-authbypass

Scanner for cPanel & WHM authentication bypass (CVE-2026-41940) that detects vulnerable versions via CRLF injection and session manipulation, with…

authenticationexploitationpenetration-testing+4
4 months ago
Mass-CVE-2025-29306 preview

Mass-CVE-2025-29306

GitHubmantanhacker/mass-cve-2025-29306

Mass Exploit for CVE-2025-29306

command-and-controlexploitationpenetration-testing+3
18 months ago
Ashwesker-CVE-2025-52691 preview

Ashwesker-CVE-2025-52691

GitHubmohammadzarnian1357/ashwesker-cve-2025-52691

CVE-2025-52691

exploitationpenetration-testingred-teaming+3
8 months ago
cdt-samba-deploy preview

cdt-samba-deploy

GitHubzanex360/cdt-samba-deploy

CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box

devsecopsexploitationpenetration-testing+3
7 months ago
React2Shell preview

React2Shell

GitLabletchupkt/react2shell

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

command-and-controlexploitationpenetration-testing+3
19 months ago
salt-rce-scanner-CVE-2020-11651-CVE-2020-11652 preview

salt-rce-scanner-CVE-2020-11651-CVE-2020-11652

GitHubappcheck-ng/salt-rce-scanner-cve-2020-11651-cve-2020-11652

Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.

command-and-controlexploitationpenetration-testing+3
15 years ago
apache__activemq_CVE-2019-0222_5-15-8 preview

apache__activemq_CVE-2019-0222_5-15-8

GitHubshoucheng3/apache__activemq_cve-2019-0222_5-15-8

Exploit for CVE-2019-0222 targeting Apache ActiveMQ 5.15.8, enabling remote code execution via crafted HTTP requests to the message broker's REST API.

exploitationpenetration-testingred-teaming+3
1 year ago
Next.js-RCE-Scanner---CVE-2025-55182-CVE-2025-66478 preview

Next.js-RCE-Scanner---CVE-2025-55182-CVE-2025-66478

GitHubmustafa1p/next.js-rce-scanner---cve-2025-55182-cve-2025-66478

An advanced vulnerability scanner for detecting **CVE-2025-55182** and **CVE-2025-66478** - critical Remote Code Execution (RCE) vulnerabilities in…

exploitationpayload-developmentpenetration-testing+3
9 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubghostn4444/cve-2025-55182

Next.js RSC RCE vulnerability scanner with multiple scan modes, WAF bypass, interactive shell, and batch scanning for authorized penetration testing.

exploitationpenetration-testingred-teaming+3
8 months ago
CTT-enhanced-VMware-vCenter preview

CTT-enhanced-VMware-vCenter

GitHubsimoesctt/ctt-enhanced-vmware-vcenter

Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known…

exploitationpenetration-testingred-teaming+2
7 months ago
BigFinger preview

BigFinger

GitHubcediegreyhat/bigfinger

CVE-2023-46747-RCE PoC

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2025-55182-Scanner preview

CVE-2025-55182-Scanner

GitHubf0xyx/cve-2025-55182-scanner

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components

exploitationpayload-developmentpenetration-testing+3
9 months ago
Previous1234…13Next