Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1742 results
CVE-2020-9484 preview

CVE-2020-9484

GitHubpentestical/cve-2020-9484

Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

educationexploitationpayload-generation+3
35
4 years ago
CVE-2014-6287 preview

CVE-2014-6287

GitHub10cks/cve-2014-6287

Rejetto http File Server 2.3.x (Reverse shell)

command-and-controlexploitationpayload-generation+3
3 years ago
through_the_wire preview

through_the_wire

GitHubjbaines-r7/through_the_wire

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

command-and-controlexploitationpayload-generation+3
1734 years ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
hfs-cve-2014-6287-exploit preview

hfs-cve-2014-6287-exploit

GitHubfrancescobrina/hfs-cve-2014-6287-exploit

Python-based exploit for CVE-2014-6287 in HTTP File Server 2.3.x, delivering a reverse shell via Base64-encoded PowerShell payload for authorized…

command-and-controleducationexploitation+5
1 year ago
CVE-2009-4623 preview

CVE-2009-4623

GitHubkernel-cyber/cve-2009-4623

Exploit for CVE-2009-4623: remote file inclusion in Advanced Comment System 1.0 enabling arbitrary PHP code execution and reverse shell via ACS_path…

exploitationpayload-generationpenetration-testing+2
14 years ago
CVE-2023-1389 preview

CVE-2023-1389

GitHubvoyag3r-security/cve-2023-1389

Proof-of-concept scripts for CVE-2023-1389, an unauthenticated command injection in TP-Link Archer AX21, providing file transfer and reverse shell…

command-and-controlexploitationpayload-development+4
173 years ago
n8n-cve-2025-68613 preview

n8n-cve-2025-68613

GitHubgagaltotal/n8n-cve-2025-68613

Authenticated RCE exploit PoC and vulnerability scanner for CVE-2025-68613 in n8n. Supports command execution, file operations, and reverse shell…

command-and-controleducationexploitation+5
9 months ago
CVE-2021-24155.rb preview

CVE-2021-24155.rb

GitHub0dayninja/cve-2021-24155.rb

WordPress Backup Guard Authenticated Remote Code Execution Exploit

exploit-frameworkspayload-developmentpenetration-testing+3
105 years ago
CVE-2024-25832-PoC preview

CVE-2024-25832-PoC

GitHub0xnslabs/cve-2024-25832-poc

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

educationexploitationinformation-gathering+3
42 years ago
CVE-2026-14483_exploit preview

CVE-2026-14483_exploit

GitHub0xdak/cve-2026-14483_exploit

Unauthenticated arbitrary file upload exploit for Realtyna WPL/Organic IDX WordPress plugin, chains PHP webshell upload to RCE, with command…

exploitationpenetration-testingred-teaming+3
1 month ago
CVE-2026-54806 preview

CVE-2026-54806

GitHubjoshuavanderpoll/cve-2026-54806

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

educationexploitationlabs-practice+5
133 months ago
CVE-2026-6009 preview

CVE-2026-6009

GitHubpumila03/cve-2026-6009

Automated PoC exploit for CVE-2026-6009, a Java deserialization RCE in Jaspersoft Reports <=7.0.3. Generates malicious .jasper payloads via ysoserial…

educationexploitationpayload-generation+4
4 months ago
CVE-2026-0766 preview

CVE-2026-0766

GitHubbitt0n/cve-2026-0766

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

code-analysiseducationexploitation+3
6 months ago
CVE-2023-45158 preview

CVE-2023-45158

GitHubyifanzhg/cve-2023-45158

Proof-of-concept exploit for CVE-2023-45158, a command injection vulnerability in web2py. Demonstrates remote code execution via crafted HTTP…

command-and-controlexploitationpayload-generation+3
42 years ago
CVE-2023-422-Chamilo-LMS-RCE preview

CVE-2023-422-Chamilo-LMS-RCE

GitHubhhesenjan/cve-2023-422-chamilo-lms-rce

Python exploit for CVE-2023-4220 in Chamilo LMS that uploads a file and delivers an unauthenticated reverse shell to a netcat listener.

exploitationpayload-developmentpenetration-testing+3
2 years ago
CVE-2026-38526 preview

CVE-2026-38526

GitHubqurclinc/cve-2026-38526

Proof-of-concept exploit for authenticated remote code execution in Krayin CRM v2.2.x via unrestricted file upload, supporting web shell and reverse…

educationexploitationpayload-generation+3
2 months ago
PoC-CVE-2025-62222 preview

PoC-CVE-2025-62222

GitHubsadisticnight/poc-cve-2025-62222

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

command-and-controleducationexploit-frameworks+7
16 months ago
Previous12…97Next