Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3742 results
POC_react2shell_CVE-2025-55182 preview

POC_react2shell_CVE-2025-55182

GitHubnkwenti-severian-ndongtsop/poc_react2shell_cve-2025-55182

Exploit for CVE-2025-55182 targeting Next.js React Server Components via prototype pollution, enabling remote code execution with command execution…

ctfeducationexploitation+4
2
9 months ago
Mirth-Connect-CVE-2023-43208 preview

Mirth-Connect-CVE-2023-43208

GitHubazrvs/mirth-connect-cve-2023-43208

Python implementation of CVE-2023-43208 Mirth Connect RCE (Unauth XStream)

educationexploitationpenetration-testing+3
27 months ago
cms-made-simple-python3 preview

cms-made-simple-python3

GitHubjagdeepsinghceh/cms-made-simple-python3

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

educationexploitationpassword-cracking+3
210 months ago
CVE-2016-10204_Webshell preview

CVE-2016-10204_Webshell

GitHub0xnullcomet/cve-2016-10204_webshell

A bash script demonstrating the manual exploitation of CVE-2016-10204 against a target endpoint, leading to upload of a php webshell.

educationexploitationpayload-generation+3
27 months ago
Offensive preview

Offensive

GitHubnaramsim/offensive

Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904

educationexploitationpenetration-testing+2
19 years ago
jinjava-cve-2026-25526-poc preview

jinjava-cve-2026-25526-poc

GitHubav4nth1ka/jinjava-cve-2026-25526-poc

Step-by-step exploit harness and proof-of-concept for CVE-2026-25526 in Jinjava, demonstrating file read, file creation, and info disclosure with…

educationexploitationlabs-practice+2
27 months ago
joomla.3.7.0exploit preview

joomla.3.7.0exploit

GitHubztrxwzy/joomla.3.7.0exploit

Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data…

ctfexploitationpenetration-testing+2
27 months ago
Variatype.htb-CVE-2025-66034 preview

Variatype.htb-CVE-2025-66034

GitHubliquid1998/variatype.htb-cve-2025-66034

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

ctfexploitationpayload-generation+3
26 months ago
CVE-2025-14598 preview

CVE-2025-14598

GitHubafnaan-ahmed/cve-2025-14598

Technical advisory and analysis of CVE-2025-14598, a critical unauthenticated SQL injection in BET e-Portal enabling database manipulation and…

database-securityeducationexploitation+3
28 months ago
CVE-2026-1560-Authenticated-Remote-Code-Execution-in-Lazy-Blocks-4.2.0 preview

CVE-2026-1560-Authenticated-Remote-Code-Execution-in-Lazy-Blocks-4.2.0

GitHubz3yr0xx/cve-2026-1560-authenticated-remote-code-execution-in-lazy-blocks-4.2.0

Proof-of-concept exploit for CVE-2026-1560, an authenticated remote code execution vulnerability in Lazy Blocks WordPress plugin, allowing…

educationexploitationpenetration-testing+3
27 months ago
CVE-2025-20393 preview

CVE-2025-20393

GitHubcyberleelawat/cve-2025-20393

Cisco is aware of a potential vulnerability.  Cisco is currently investigating and will update these details as appropriate as more…

educationexploitationinformation-gathering+4
29 months ago
CVE-2021-22911-RocketChat preview

CVE-2021-22911-RocketChat

GitHubfaridi-m/cve-2021-22911-rocketchat

Exploit for Rocket.Chat 3.12.1 RCE via pre-auth NoSQL injection, leaking admin TOTP secret and password reset token to achieve remote code execution…

educationexploitationpayload-development+3
27 months ago
react2shell preview

react2shell

GitHubdr4xp/react2shell

A critical vulnerability in React Server Components affecting React 19 (CVE-2025-55182) and frameworks that use it like Next.js (CVE-2025-66478).

ctfeducationexploitation+3
210 months ago
CVE-2019-14234 preview

CVE-2019-14234

GitHubmalvika-thakur/cve-2019-14234

POC-Django JSONField/HStoreField SQL Injection Vulnerability (CVE-2019-14234)

database-securityeducationexploitation+3
23 years ago
CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC- preview

CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC-

GitHubudayveer17/cve-2025-2945-pgadmin4-authenticated-rce-poc-

Proof-of-concept exploit for authenticated remote code execution in pgAdmin4 (CVE-2025-2945) via SQL Editor abuse. Designed for authorized security…

educationexploitationpenetration-testing+3
210 months ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
Apache-HTTP-Server-2.4.50-RCE preview

Apache-HTTP-Server-2.4.50-RCE

GitHubzyx2440/apache-http-server-2.4.50-rce

Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for…

educationexploitationpenetration-testing+3
22 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubroycampos/cve-2025-29927

CVE-2025-29927 Exploit Checker

educationexploitationinformation-gathering+3
21 year ago
Previous1…99100Next