Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1010 results
deep-C preview

deep-C

GitHubkishorbal/deep-c

Android deeplink misconfiguration detector and exploitation tool

ai-securityandroid-securitydynamic-analysis-sandboxing+8
917 months ago
juniper-rce_cve-2023-36844 preview

juniper-rce_cve-2023-36844

GitHubwatchtowrlabs/juniper-rce_cve-2023-36844

Proof-of-concept exploit chaining four CVEs (CVE-2023-36844-47) for pre-authentication remote code execution on Juniper JunOS SRX and EX series…

exploitationpayload-developmentpenetration-testing+3
1153 years ago
Havoc-C2-SSRF-poc preview

Havoc-C2-SSRF-poc

GitHubchebuya/havoc-c2-ssrf-poc

CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit

command-and-controlexploitationpenetration-testing+3
762 years ago
ASPX_WebShell_COFFLoader preview

ASPX_WebShell_COFFLoader

GitHubepotseluevskaya/aspx_webshell_coffloader

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

command-and-controlpayload-developmentpenetration-testing+3
1366 months ago
CVE-2020-2551 preview

CVE-2020-2551

GitHubjas502n/cve-2020-2551

Proof-of-concept exploit for CVE-2020-2551, demonstrating remote code execution in Oracle WebLogic Server via the IIOP protocol. Includes default…

exploitationpenetration-testingred-teaming+2
806 years ago
CVE-2022-23808 preview

CVE-2022-23808

GitHubdipakpanchal05/cve-2022-23808

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

exploitationpenetration-testingred-teaming+3
1151 year ago
CVE-2017-7092-PoC preview

CVE-2017-7092-PoC

GitHubxuechiyaobai/cve-2017-7092-poc

This is the Pwn2Own 2017 Safari backup vul's exploit.

exploitationpenetration-testingred-teaming+2
1167 years ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubjweny/cve-2022-23131

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

exploitationpenetration-testingred-teaming+2
954 years ago
watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 preview

watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-preauth-rce-cve-2026-8452

CVE-2026-8452 PreAuth RCE

exploitationpayload-developmentred-teaming+3
631 month ago
Log4jHorizon preview

Log4jHorizon

GitHubpuzzlepeaches/log4jhorizon

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

exploitationpayload-developmentpenetration-testing+4
1204 years ago
CVE-2024-53677-S2-067 preview

CVE-2024-53677-S2-067

GitHubtam-k592/cve-2024-53677-s2-067

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

exploitationpayload-developmentpenetration-testing+3
951 year ago
Fortijump-Exploit-CVE-2024-47575 preview

Fortijump-Exploit-CVE-2024-47575

GitHubwatchtowrlabs/fortijump-exploit-cve-2024-47575

Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

exploitationpenetration-testingred-teaming+3
971 year ago
CVE-2018-17246 preview

CVE-2018-17246

GitHubmpgn/cve-2018-17246

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

exploitationpayload-developmentpenetration-testing+3
656 years ago
CVE-2023-25194 preview

CVE-2023-25194

GitHubohnonoyesyes/cve-2023-25194

Proof-of-concept exploit for CVE-2023-25194, a JNDI injection vulnerability in Apache Kafka Connect enabling remote code execution via crafted…

command-and-controlexploitationpenetration-testing+3
923 years ago
php-8.1.0-dev-backdoor-rce preview

php-8.1.0-dev-backdoor-rce

GitHubflast101/php-8.1.0-dev-backdoor-rce

PHP 8.1.0-dev Backdoor System Shell Script

exploitationpenetration-testingred-teaming+2
955 years ago
CVE-2023-22515 preview

CVE-2023-22515

GitHubad-calcium/cve-2023-22515

Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具

authenticationexploitationpenetration-testing+3
1102 years ago
moltbot-1click-rce preview

moltbot-1click-rce

GitHubethiack/moltbot-1click-rce

Clawdbot/Moltbot/OpenClaw One-click RCE PoC 🦞 (CVE-2026-25253)

exploitationpenetration-testingred-teaming+2
928 months ago
CVE-2025-25257 preview

CVE-2025-25257

GitHub0xbigshaq/cve-2025-25257

Exploit for CVE-2025-25257, a FortiWeb Fabric RCE vulnerability, with a full working exploit and a PoC for file read/write.

exploitationpenetration-testingred-teaming+2
641 year ago
Previous1…567…57Next