Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1742 results
CVE-2024-46986 preview

CVE-2024-46986

GitHubvidura2/cve-2024-46986

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

educationexploitationpayload-development+3
3
2 years ago
CVE-2025-60787_PoC preview

CVE-2025-60787_PoC

GitHublil0xplorer/cve-2025-60787_poc

Authenticated RCE exploit for MotionEye <= 0.43.1b4 via client-side validation bypass on the image_file_name field. Includes reverse shell payload…

exploitationpenetration-testingred-teaming+3
26 months ago
CVE-2023-4220-RCE preview

CVE-2023-4220-RCE

GitHubbueno-armando/cve-2023-4220-rce

Python exploit for CVE-2023-4220, an unauthenticated remote code execution in Chamilo LMS via unrestricted file upload, enabling web shell deployment…

exploitationpenetration-testingremote-access-tool+2
11 year ago
CVE-2023-50564 preview

CVE-2023-50564

GitHubmrterrestrial/cve-2023-50564

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

exploitationpayload-generationpenetration-testing+3
11 year ago
cve-2022-23636-poc preview

cve-2022-23636-poc

GitHubcyhe50/cve-2022-23636-poc

Authenticated remote code execution exploit for m1k1o's Blog v1.3 via unvalidated file upload, with webshell deployment and reverse shell…

educationexploitationpayload-generation+3
5 months ago
CVE-2021-22205 preview

CVE-2021-22205

GitHubccordeiro/cve-2021-22205

Python exploit for CVE-2021-22205, a remote command execution in GitLab CE/EE via image file parsing. Supports vulnerability checking, batch…

command-and-controlexploitationpenetration-testing+3
10 months ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubassassinukg/cve-2021-22204

Exploit script for CVE-2021-22204, an ExifTool RCE via malicious DjVu files, with manual exploitation steps and reverse shell payloads.

code-analysisexploitationpayload-development+3
274 years ago
CVE-2025-6002 preview

CVE-2025-6002

GitHubschn1tzelme1ster/cve-2025-6002

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

exploitationpayload-generationpenetration-testing+3
6 months ago
CVE-2024-25641-Exploit-for-Cacti-1.2.26 preview

CVE-2024-25641-Exploit-for-Cacti-1.2.26

GitHubregantemudo/cve-2024-25641-exploit-for-cacti-1.2.26

Automated exploit for CVE-2024-25641 targeting Cacti 1.2.26. Achieves remote code execution via authenticated arbitrary file write in the Package…

educationexploitationpayload-development+4
1 year ago
Elastix-2.2.0-CVE-2012-4869 preview

Elastix-2.2.0-CVE-2012-4869

GitHubcyberdesu/elastix-2.2.0-cve-2012-4869

Python exploit script for Elastix 2.2.0 LFI vulnerability (CVE-2012-4869) enabling remote code execution via Perl reverse shell payload injection.

educationexploitationpayload-development+3
1 year ago
CVE-2026-67401 preview

CVE-2026-67401

GitHubaxedos/cve-2026-67401

Python proof-of-concept for CVE-2026-67401, an authenticated SQL injection in cPanel EmailTrack that allows arbitrary file write as root via SQLite…

exploitationpayload-developmentpenetration-testing+2
317 days ago
CVE-2023-24249-PoC preview

CVE-2023-24249-PoC

GitHubldb33/cve-2023-24249-poc

Proof-of-concept exploit for CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin, enabling web shell deployment for penetration…

ctfexploitationpayload-generation+3
1 year ago
CVE-2024-7627 preview

CVE-2024-7627

GitHublkmn1/cve-2024-7627

Proof-of-concept exploit for CVE-2024-7627, an unauthenticated remote code execution vulnerability in Bit File Manager WordPress plugin. Automates…

exploitationpayload-developmentpenetration-testing+3
11 months ago
CVE-2024-5084 preview

CVE-2024-5084

GitHubraeezrbr/cve-2024-5084

Exploit for CVE-2024-5084: unauthenticated arbitrary file upload in Hash Form WordPress plugin, enabling remote code execution via Python script with…

exploitationpayload-generationpenetration-testing+3
1 year ago
LFISuite preview

LFISuite

GitHubd35m0nd142/lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

exploitationpayload-generationpenetration-testing+3
2.0k8 years ago
CVE-2023-4220-PoC preview

CVE-2023-4220-PoC

GitHubsn0wbaall/cve-2023-4220-poc

Automated proof-of-concept exploit for CVE-2023-4220 in Chamilo LMS, enabling arbitrary file upload and remote code execution via unauthenticated…

exploitationpayload-generationpenetration-testing+3
7 months ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubcai-niao98/cve-2022-26134

Exploit for CVE-2022-26134 targeting Confluence Server with remote command execution and reverse shell capabilities. Supports batch scanning and…

command-and-controlexploitationpenetration-testing+2
34 years ago
cve-2024-56348 preview

cve-2024-56348

GitHubjoshuavanderpoll/cve-2024-56348

Go-based exploit for CVE-2024-56348 targeting JetBrains TeamCity authentication bypass and remote code execution. Provides interactive shell, reverse…

authenticationexploitationpenetration-testing+4
36 months ago
Previous123…97Next