Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1010 results
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
2
1 month ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5334 years ago
CVE-2024-13346 preview

CVE-2024-13346

GitHubtausifzaman/cve-2024-13346

Avada Theme < 7.11.14 - Unauthenticated Arbitrary Shortcode Execution CVE-2024-13346 exploit script

exploitationpenetration-testingred-teaming+2
1 year ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.9k4 months ago
CVE-2026-76060_ZoneMinder_CommandInjection-PoC preview

CVE-2026-76060_ZoneMinder_CommandInjection-PoC

GitHubinvestigato/cve-2026-76060_zoneminder_commandinjection-poc

Proof-of-concept exploit for CVE-2026-76060, an OS command injection in ZoneMinder's event export, demonstrating RCE via crafted monitor names.

command-and-controlexploitationpenetration-testing+3
129 days ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubhualy13/cve-2025-55182

Automated proof-of-concept exploit for Next.js RCE (CVE-2025-55182) with interactive shell, batch scanning, and advanced payload encoding for…

exploitationpayload-developmentpenetration-testing+3
49 months ago
pythia-sql-clairvoyance preview

pythia-sql-clairvoyance

GitHubrodhnin/pythia-sql-clairvoyance

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlerdevsecops+5
24 months ago
CVE-2024-27348-HugeGraph-RCE preview

CVE-2024-27348-HugeGraph-RCE

GitHubakelaqe/cve-2024-27348-hugegraph-rce

Advanced PoC exploit for CVE-2024-27348, achieving reliable RCE in Apache HugeGraph via sandbox bypass and non-blind command execution.

exploitationpayload-developmentpenetration-testing+3
16 months ago
CVE-2018-15877-RCE preview

CVE-2018-15877-RCE

GitHubcinnamon1212/cve-2018-15877-rce

Wordpress Plainview Activity Monitor Plugin RCE (20161228)

exploitationpenetration-testingred-teaming+2
15 years ago
Next.js-RCE-Scanner---CVE-2025-55182-CVE-2025-66478 preview

Next.js-RCE-Scanner---CVE-2025-55182-CVE-2025-66478

GitHubmustafa1p/next.js-rce-scanner---cve-2025-55182-cve-2025-66478

An advanced vulnerability scanner for detecting **CVE-2025-55182** and **CVE-2025-66478** - critical Remote Code Execution (RCE) vulnerabilities in…

exploitationpayload-developmentpenetration-testing+3
9 months ago
T3MP3ST preview

T3MP3ST

GitHubelder-plinius/t3mp3st

autonomous red teaming platform; multi-agent offensive-security meta-harness

ai-securitybinary-analysiscloud-security+9
6.3k19 days ago
Claude-Red preview

Claude-Red

GitHubsnailsploit/claude-red

Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and…

ai-securitycurated-resourceseducation+8
6.8k7 days ago
CVE-2017-7269 preview

CVE-2017-7269

GitHubh3x0v3rl0rd/cve-2017-7269

Exploit for CVE-2017-7269 targeting IIS 6.0 WebDAV remote code execution vulnerability. Enables buffer overflow exploitation on legacy Windows…

exploitationpenetration-testingred-teaming+2
55 years ago
CVE-2019-19781-exploit preview

CVE-2019-19781-exploit

GitHubk-fire/cve-2019-19781-exploit

Exploit for CVE-2019-19781 targeting Citrix ADC/NetScaler vulnerability. Provides automated exploitation for penetration testing and red team…

exploitationpenetration-testingred-teaming+2
34 years ago
Exploit-CVE-2017-5633 preview

Exploit-CVE-2017-5633

GitHubcardangi/exploit-cve-2017-5633

Python exploit for CVE-2017-5633 targeting Apache Struts2 remote code execution vulnerability. Designed for penetration testing and red team…

exploitationpenetration-testingred-teaming+2
9 years ago
CVE-2021-22986 preview

CVE-2021-22986

GitHubkiri-48/cve-2021-22986

Python exploit script for CVE-2021-22986, targeting a remote code execution vulnerability in F5 BIG-IP devices. Provides URL-based exploitation for…

exploitationpenetration-testingred-teaming+2
5 years ago
cve-2017-7269picture preview

cve-2017-7269picture

GitHubwhitehat001/cve-2017-7269picture

Exploit for CVE-2017-7269 targeting a remote code execution vulnerability in Microsoft IIS WebDAV. Designed for penetration testing and red team…

exploitationpenetration-testingred-teaming+2
9 years ago
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k4 months ago
Previous12…57Next