Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
156 results
CVE-2019-2725 preview

CVE-2019-2725

GitHubwelove88888/cve-2019-2725

Python-based exploit for CVE-2019-2725 (Oracle WebLogic) providing command execution and webshell upload targeting versions 10.3.6 and 12.1.3.

command-and-controlexploitationpayload-generation+3
2
7 years ago
Oracle-E-BS-CVE-2022-21587-Exploit preview

Oracle-E-BS-CVE-2022-21587-Exploit

GitHubrockmelodies/oracle-e-bs-cve-2022-21587-exploit

Oracle E-BS CVE-2022-21587 Exploit

exploitationpayload-generationpenetration-testing+2
23 years ago
CVE-2018-2628all preview

CVE-2018-2628all

GitHubshadowshusky/cve-2018-2628all

Batch vulnerability scanner for CVE-2018-2628 in Oracle WebLogic, with configurable timeout and IP list input for automated detection.

exploitationpenetration-testingreconnaissance+2
28 years ago
CVE-2020-14645 preview

CVE-2020-14645

GitHubdaboquan/cve-2020-14645

Java-based exploit for CVE-2020-14645 targeting Oracle WebLogic T3 protocol with JNDI injection for remote code execution.

exploitationpayload-generationpenetration-testing+2
36 years ago
CVE-2026-43914-PoC preview

CVE-2026-43914-PoC

GitHubboreas37/cve-2026-43914-poc

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

exploitationpassword-attackspenetration-testing+2
11 month ago
CVE-2026-60206 preview

CVE-2026-60206

GitHubdebajyoti0-0/cve-2026-60206

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

authenticationexploitationpenetration-testing+2
12 months ago
CVE-2026-67620-poc preview

CVE-2026-67620-poc

GitHubabdugafforov-bobur/cve-2026-67620-poc

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

cloud-securityexploitationinformation-gathering+4
12 months ago
CVE-2016-3510 preview

CVE-2016-3510

GitHubbabyteam1024/cve-2016-3510

Proof-of-concept exploit for CVE-2016-3510, a Java deserialization vulnerability in Oracle WebLogic Server, demonstrating remote code execution.

exploitationpayload-developmentpenetration-testing+2
15 years ago
CVE-2020-2883 preview

CVE-2020-2883

GitHubfancydoessecurity/cve-2020-2883

Python-based proof-of-concept exploit for CVE-2020-2883 targeting Oracle WebLogic Server with command execution capabilities.

exploitationpayload-generationpenetration-testing+2
25 years ago
CVE-2019-2725 preview

CVE-2019-2725

GitHubdavidmthomsen/cve-2019-2725

Exploit for CVE-2019-2725 targeting Oracle WebLogic Server deserialization vulnerability, enabling remote code execution for penetration testing and…

exploitationpenetration-testingred-teaming+2
17 years ago
CVE-2024-20931-Poc preview

CVE-2024-20931-Poc

GitHubleocodefocus/cve-2024-20931-poc

Proof-of-concept exploit for CVE-2024-20931 targeting a remote code execution vulnerability in Oracle WebLogic Server. Includes payload generation…

exploitationpayload-developmentpenetration-testing+2
12 years ago
CVE-2018-2628 preview

CVE-2018-2628

GitHubherantong/cve-2018-2628

Python-based exploit for CVE-2018-2628 targeting Oracle WebLogic Server, providing vulnerability detection and remote shell access via JSP payload…

exploitationpayload-generationpenetration-testing+3
19 months ago
CVE-2025-61882-Oracle-BI-Publisher-RCE preview

CVE-2025-61882-Oracle-BI-Publisher-RCE

GitHubgeorge0papasotiriou/cve-2025-61882-oracle-bi-publisher-rce

Proof-of-concept exploit for CVE-2025-61882: unauthenticated remote code execution via insecure deserialization in Oracle BI Publisher integration…

exploitationpenetration-testingred-teaming+2
18 months ago
oracle-xxe-sqli preview

oracle-xxe-sqli

GitHubsecurityartwork/oracle-xxe-sqli

Automated Oracle CVE-2014-6577 exploitation via SQLi

database-securityexploitationpenetration-testing+2
8 years ago
CVE-2022-21306 preview

CVE-2022-21306

GitHubhktalent/cve-2022-21306

Proof-of-concept exploit for CVE-2022-21306 targeting Oracle WebLogic Server. Includes multiple HTTP-based detection and exploitation scripts for…

exploitationpenetration-testingreconnaissance+2
13 years ago
CVE-2026-21994 preview

CVE-2026-21994

GitHubg0w6y/cve-2026-21994

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

authenticationcloud-securityexploitation+3
6 months ago
weblogic_cve-2019-2890 preview

weblogic_cve-2019-2890

GitHubfreeide/weblogic_cve-2019-2890

Exploit for CVE-2019-2890 targeting Oracle WebLogic Server via XXE injection and deserialization, enabling remote code execution through crafted…

exploitationpayload-generationpenetration-testing+2
6 years ago
cve-2018-2628 preview

cve-2018-2628

GitHubbabyteam1024/cve-2018-2628

Exploit for CVE-2018-2628, a Java deserialization vulnerability in Oracle WebLogic Server, enabling remote code execution.

exploitationexploit-frameworkspenetration-testing+3
5 years ago
Previous1…6789Next