Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1759 results
CVE-2025-55182_RCE_Exploit preview

CVE-2025-55182_RCE_Exploit

GitHubnexxp90/cve-2025-55182_rce_exploit

Python-based RCE detection tool that sends crafted POST requests, analyzes responses for execution indicators, and supports batch scanning with…

exploitationpayload-generationpenetration-testing+2
5 months ago
CVE-2020-24972 preview

CVE-2020-24972

GitHubspiralbl0ck/cve-2020-24972

Proof-of-concept demonstrating DLL execution via Qt platformpluginpath option in Kleopatra, exploiting CVE-2020-24972 through custom URI schemes.

binary-exploitationexploitationpayload-generation+2
11 year ago
CVE-2022-29464 preview

CVE-2022-29464

GitHublinjacck/cve-2022-29464

CVE-2022-29464 exploit tool with detection and arbitrary file upload capabilities, supporting single URL and batch scanning with custom webshell…

exploitationpayload-generationpenetration-testing+2
14 years ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
8 months ago
CVE-2020-1938_Ghostcat-PoC preview

CVE-2020-1938_Ghostcat-PoC

GitHubabrewer251/cve-2020-1938_ghostcat-poc

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

exploitationinformation-gatheringpayload-generation+3
8 months ago
CSRF-via-stored-XSS-for-PrivEsc preview

CSRF-via-stored-XSS-for-PrivEsc

GitHubmexeck88/csrf-via-stored-xss-for-privesc

Proof-of-concept exploit for CVE-2025-26153: stored XSS in Chamilo LMS forum threads enabling privilege escalation from regular user to admin via…

educationexploitationpayload-development+4
6 months ago
exploit_cve_2025_67303 preview

exploit_cve_2025_67303

GitHubmateraj2/exploit_cve_2025_67303

Proof-of-concept exploit for CVE-2025-67303 targeting remote code execution in ComfyUI Manager via malicious custom node installation. Includes…

exploitationpayload-generationpenetration-testing+2
7 months ago
CVE-2017-11882 preview

CVE-2017-11882

GitHubtzwlhack/cve-2017-11882

Python-based exploit generator for CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) with support for custom shellcode, mshta payloads,…

exploitationpayload-generationpenetration-testing+2
14 years ago
CVE-2021-44228_dockernize preview

CVE-2021-44228_dockernize

GitHubqw3rtyou/cve-2021-44228_dockernize

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

educationexploitationlabs-practice+3
11 year ago
CVE-2024-28397-RCE preview

CVE-2024-28397-RCE

GitHubharutomo-jp/cve-2024-28397-rce

Python exploit script for CVE-2024-28397 targeting js2py <= v0.74. Supports reverse shell and custom command execution via HTTP endpoint.

exploitationpayload-generationpenetration-testing+2
11 year ago
CVE-2018-7600-Remote-Code-Execution preview

CVE-2018-7600-Remote-Code-Execution

GitHubsyedghufranraza/cve-2018-7600-remote-code-execution

Python-based proof-of-concept exploit for CVE-2018-7600 (Drupalgeddon2) enabling remote code execution on vulnerable Drupal sites, with multi-target…

educationexploitationpayload-generation+3
1 year ago
CVE-2025-47812 preview

CVE-2025-47812

GitHubpevinkumar10/cve-2025-47812

Python exploit for CVE-2025-47812 targeting WingFTP Server, enabling unauthenticated remote code execution via NULL byte injection in username field,…

exploitationpayload-generationpenetration-testing+3
1 year ago
text4shell-exploit preview

text4shell-exploit

GitHubsyndicate27/text4shell-exploit

A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache…

educationexploitationpayload-generation+3
1 year ago
CVE-2018-5146 preview

CVE-2018-5146

GitHubf01965/cve-2018-5146

Proof-of-concept exploit and custom payload generator for CVE-2018-5146, including crafted OGG POC file and HTML-based exploit with CRC32 calculation…

binary-analysisexploitationpayload-generation+2
4 years ago
CVE-2018-19422 preview

CVE-2018-19422

GitHubdrew-alleman/cve-2018-19422

Subrion File Upload Bypass to RCE and Custom File Upload (Authenticated) POC

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2021-44228-Apache-Log4j preview

CVE-2021-44228-Apache-Log4j

GitHublonecloud/cve-2021-44228-apache-log4j

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) demonstrating remote code execution via JNDI injection with LDAP server and custom payload…

command-and-controlexploitationpayload-generation+3
4 years ago
CVE-2024-12594 preview

CVE-2024-12594

GitHubrandomrobbiebf/cve-2024-12594

ALL In One Custom Login Page <= 7.1.1 - Missing Authorization to Authenticated (Subscriber+)Privilege Escalation

exploitationpenetration-testingprivilege-escalation+2
1 year ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubyzee00/cve-2017-12617

Python3 exploit for CVE-2017-12617 (Apache Tomcat JSP upload RCE) with single URL and batch scanning modes, supporting custom payload deployment.

exploitationpayload-generationpenetration-testing+2
2 years ago
Previous1…345…98Next