Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
840 results
Apache-Struts-v4 preview

Apache-Struts-v4

GitHubs1kr10s/apache-struts-v4

Exploit script targeting 5 Apache Struts RCE vulnerabilities (CVE-2013-2251, CVE-2017-5638, CVE-2017-9805, CVE-2018-11776, CVE-2019-0230) with PHP…

exploitationpayload-generationvulnerability-analysis+1
206
5 years ago
htb-sau-exploit-chain preview

htb-sau-exploit-chain

GitHubtombstoneghost/htb-sau-exploit-chain

Automated exploit chain for HTB Sau — CVE-2023-27163 (SSRF) + Maltrail Unauthenticated RCE → Reverse Shell

ctfeducationexploitation+3
5 months ago
CVE-2022-22963_Reverse-Shell-Exploit preview

CVE-2022-22963_Reverse-Shell-Exploit

GitHubj0ey17/cve-2022-22963_reverse-shell-exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify…

exploitationpayload-generationpenetration-testing+3
243 years ago
Pluck-CMS-v4.7.18-Remote-Code-Execution-CVE-2023-50564 preview

Pluck-CMS-v4.7.18-Remote-Code-Execution-CVE-2023-50564

GitHub0xdtc/pluck-cms-v4.7.18-remote-code-execution-cve-2023-50564

Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubahmadf77/cve-2026-23744

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

command-and-controlexploitationpayload-development+3
5 months ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubgraphite-org/cve-2024-4577

Shell script to scan domains for CVE-2024-4577 PHP remote code execution vulnerability via crafted POST requests, exporting vulnerable targets for…

exploitationpenetration-testingreconnaissance+2
2 years ago
SHELL-POC-CVE-2022-46169 preview

SHELL-POC-CVE-2022-46169

GitHubrdbbb3/shell-poc-cve-2022-46169

Bash proof-of-concept script that exploits CVE-2022-46169 to send a reverse shell payload to a vulnerable Cacti instance.

exploitationpayload-generationpenetration-testing+2
1 year ago
Craft-CMS-Exploit preview

Craft-CMS-Exploit

GitHubdiegaccio/craft-cms-exploit

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

exploitationpenetration-testingred-teaming+3
52 years ago
WBCE-v1.6.3-Authenticated-RCE preview

WBCE-v1.6.3-Authenticated-RCE

GitHubswammers8/wbce-v1.6.3-authenticated-rce

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

exploitationpayload-generationremote-access-tool+1
1 year ago
CVE-2023-50564 preview

CVE-2023-50564

GitHubrwexecute/cve-2023-50564

Python Script to exploit CVE-2023-50564

educationexploitationpayload-generation+3
1 year ago
CVE-2026-27626-POC preview

CVE-2026-27626-POC

GitHubcobrastrike62/cve-2026-27626-poc

Proof-of-concept exploit script for command injection (CVE-2026-27626) in OliveTin's password argument handling, enabling RCE via crafted API…

exploitationpayload-generationpenetration-testing+2
22 months ago
CVE-2023-50564 preview

CVE-2023-50564

GitHubmrterrestrial/cve-2023-50564

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubr4y-br/cve-2022-22963

Python automation script that reproduces CVE-2022-22963, a critical SpEL injection in Spring Cloud Function, enabling reverse shell in authorized lab…

ctfeducationexploitation+3
1 month ago
CVE-2021-30853 preview

CVE-2021-30853

GitHubshubham0d/cve-2021-30853

Proof-of-concept script that demonstrates bypassing macOS Gatekeeper, notarization, and XProtect checks by exploiting CVE-2021-30853, allowing…

exploitationpayload-developmentweb-application-exploitation
24 years ago
CVE-2024-2389 preview

CVE-2024-2389

GitHubadhikara13/cve-2024-2389

Python script that exploits CVE-2024-2389 in Progress Kemp Flowmon to execute arbitrary commands and establish a reverse shell via the…

educationexploitationremote-access-tool+2
22 years ago
CVE-2026-0740 preview

CVE-2026-0740

GitHubmurrez/cve-2026-0740

Exploit script for CVE-2026-0740 targeting Ninja Forms file upload endpoints to upload a PHP shell, scanning a list of URLs and logging successful…

exploitationvulnerability-scannersweb-application-exploitation+1
14 months ago
CVE-2022-41544 preview

CVE-2022-41544

GitHubh3x0v3rl0rd/cve-2022-41544

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-46986 preview

CVE-2024-46986

GitHubvidura2/cve-2024-46986

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

educationexploitationpayload-development+3
31 year ago
Previous123…47Next