Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1263 results
CVE-2026-58457 preview

CVE-2026-58457

GitHubj4ck3lsyn-gen2/cve-2026-58457

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

command-and-controleducationexploitation+7
2
2 months ago
CVE-2022-44149 preview

CVE-2022-44149

GitHubgeniuszly/cve-2022-44149

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

exploitationpayload-generationpenetration-testing+3
52 years ago
ysoserial.net preview

ysoserial.net

GitHubpwntester/ysoserial.net

Deserialization payload generator for a variety of .NET formatters

exploitationpayload-generationpenetration-testing+1
3.8k1 month ago
XSS-LOADER preview

XSS-LOADER

GitHubcapture0x/xss-loader

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

payload-generationpenetration-testingwaf-bypass+2
6215 months ago
CVE-2023-38831-winrar-exploit preview

CVE-2023-38831-winrar-exploit

GitHubb1tg/cve-2023-38831-winrar-exploit

CVE-2023-38831 winrar exploit generator

exploitationpayload-generationpenetration-testing+3
7832 years ago
xssless preview

xssless

GitHubmandatoryprogrammer/xssless

An automated XSS payload generator written in python.

payload-generationpenetration-testingscripting-automation+1
31310 years ago
log4j-payload-generator preview

log4j-payload-generator

GitHubwoodpecker-appstore/log4j-payload-generator

Log4j jndi injects the Payload generator

exploitationpayload-generationpenetration-testing+1
4894 years ago
Apache-Struts-v4 preview

Apache-Struts-v4

GitHubs1kr10s/apache-struts-v4

Exploit script targeting 5 Apache Struts RCE vulnerabilities (CVE-2013-2251, CVE-2017-5638, CVE-2017-9805, CVE-2018-11776, CVE-2019-0230) with PHP…

exploitationpayload-generationvulnerability-analysis+1
2055 years ago
Webmin-CVE-2022-0824-revshell preview

Webmin-CVE-2022-0824-revshell

GitHubfaisalfs10x/webmin-cve-2022-0824-revshell

Post-authentication reverse shell exploit for Webmin <=1.984 leveraging CVE-2022-0824 File Manager privilege escalation. Downloads and executes a CGI…

exploitationpayload-generationpenetration-testing+3
1124 years ago
ppsx-file-generator preview

ppsx-file-generator

GitHubtemesgeny/ppsx-file-generator

ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)

exploitationpayload-generationpenetration-testing+3
668 years ago
ZIPFileRaider preview

ZIPFileRaider

GitHubdestine21/zipfileraider

ZIP File Raider - Burp Extension for ZIP File Payload Testing

fuzzingpayload-generationpenetration-testing+2
716 years ago
watchTowr-vs-FortiWeb-CVE-2025-25257 preview

watchTowr-vs-FortiWeb-CVE-2025-25257

GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

Detection artifact generator for FortiWeb CVE-2025-25257, exploiting unauthenticated SQL injection to achieve remote code execution via hex-encoded…

exploitationpayload-generationpenetration-testing+3
1001 year ago
CVE-2020-17530 preview

CVE-2020-17530

GitHubka1n4t/cve-2020-17530

Proof-of-concept exploit for CVE-2020-17530 (Apache Struts2 S2-061) with OGNL injection payload for remote code execution testing.

exploitationpayload-generationpenetration-testing+2
645 years ago
masta-cve-2026-48907 preview

masta-cve-2026-48907

GitHubgh1mau/masta-cve-2026-48907

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

exploitationpayload-generationpenetration-testing+4
643 months ago
watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882 preview

watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

GitHubwatchtowrlabs/watchtowr-vs-oracle-e-business-suite-cve-2025-61882

Generates detection artifacts for Oracle E-Business Suite CVE-2025-61882 by serving a reverse shell payload to verify pre-auth RCE.

exploitationpayload-generationpenetration-testing+3
551 year ago
loxs-optimized preview

loxs-optimized

GitHubmomika233/loxs-optimized

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

payload-generationpenetration-testingscripting-automation+3
451 year ago
CVE-2022-40146_Exploit_Jar preview

CVE-2022-40146_Exploit_Jar

GitHubcckuailong/cve-2022-40146_exploit_jar

Java-based exploit for Apache Batik SSRF to RCE (CVE-2022-40146) with payload generation via jar and ecmascript, enabling remote class loading…

exploitationpayload-generationpenetration-testing+3
313 years ago
watchTowr-vs-FreePBX-CVE-2025-57819 preview

watchTowr-vs-FreePBX-CVE-2025-57819

GitHubwatchtowrlabs/watchtowr-vs-freepbx-cve-2025-57819

Python-based detection artifact generator for CVE-2025-57819, exploiting FreePBX pre-auth RCE via SQL injection and auth bypass to deploy webshells…

exploitationpayload-generationpenetration-testing+3
301 year ago
Previous12…71Next