Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
230 results
CVE-2017-10271 preview

CVE-2017-10271

GitHubc0mmand3ropsec/cve-2017-10271

Unauthenticated remote code execution exploit for Oracle WebLogic CVE-2017-10271. Provides XML payload and endpoint list for penetration testing of…

command-and-controlexploitationpayload-generation+3
140
8 years ago
CVE-2017-10271 preview

CVE-2017-10271

GitHubkkirsche/cve-2017-10271

Python and Metasploit exploit for Oracle WebLogic WLS-WSAT deserialization vulnerability (CVE-2017-10271) with detection scanning and remote code…

exploitationexploit-frameworkspayload-generation+3
1284 years ago
Weblogic-CVE-2023-21839 preview

Weblogic-CVE-2023-21839

GitHubdxask88ma/weblogic-cve-2023-21839

Java-based exploit for CVE-2023-21839 targeting Oracle WebLogic Server versions 12.2.1.3.0 and 12.2.1.4.0 via LDAP injection for remote code…

exploitationpayload-generationpenetration-testing+3
2403 years ago
CVE-2018-3191 preview

CVE-2018-3191

GitHubjas502n/cve-2018-3191

Exploit for CVE-2018-3191 targeting Oracle WebLogic Server via T3 protocol, enabling unauthenticated remote code execution with JNDI payload…

command-and-controlexploitationpayload-generation+3
687 years ago
CVE-2020-2551 preview

CVE-2020-2551

GitHubjas502n/cve-2020-2551

Proof-of-concept exploit for CVE-2020-2551, demonstrating remote code execution in Oracle WebLogic Server via the IIOP protocol. Includes default…

exploitationpenetration-testingred-teaming+2
806 years ago
ysoserial-cve-2018-2628 preview

ysoserial-cve-2018-2628

GitHubtdy218/ysoserial-cve-2018-2628

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

exploitationpayload-developmentpenetration-testing+2
1148 years ago
CVE-2019-2890 preview

CVE-2019-2890

GitHubl1nk3rlin/cve-2019-2890

PoC exploit for CVE-2019-2890 targeting Oracle WebLogic, using ysoserial JRMP payload for remote command execution via serialized object…

command-and-controlexploitationpayload-generation+3
856 years ago
SHIRO-721 preview

SHIRO-721

GitHubjas502n/shiro-721

RememberMe Padding Oracle Vulnerability RCE

cryptographyexploitationpenetration-testing+2
726 years ago
rustpad preview

rustpad

GitHubkibouo/rustpad

Multi-threaded Padding Oracle attacks against any service. Written in Rust.

cryptographyexploitationpenetration-testing+1
1013 years ago
POC-CVE-2026-60206 preview

POC-CVE-2026-60206

GitHubimbas007/poc-cve-2026-60206

cve cve-2026-60206 weblogic saml exploit poc vulnerability oracle scanner security

authentication-authorizationexploitationpenetration-testing+4
352 months ago
CVE-2021-35587 preview

CVE-2021-35587

GitHubzz-socmap/cve-2021-35587

Proof-of-concept exploit for CVE-2021-35587, an unauthenticated remote code execution vulnerability in Oracle Access Manager, allowing full takeover…

exploitationpenetration-testingred-teaming+2
424 years ago
CVE-2017-10366_peoplesoft preview

CVE-2017-10366_peoplesoft

GitHubblazeinfosec/cve-2017-10366_peoplesoft

CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit

exploitationpayload-generationpenetration-testing+2
258 years ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubmhtsec/cve-2026-85706

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

data-exfiltrationexploitationinformation-gathering+5
1229 days ago
CVE-2022-21371 preview

CVE-2022-21371

GitHubmr-xn/cve-2022-21371

Oracle WebLogic Server 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 Local File Inclusion

exploitationinformation-gatheringpenetration-testing+2
264 years ago
OAMBuster preview

OAMBuster

GitHubredtimmy/oambuster

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

cryptographyexploitationpenetration-testing+2
247 years ago
CVE-2022-21587-POC preview

CVE-2022-21587-POC

GitHubhieuminhnv/cve-2022-21587-poc

Proof-of-concept exploit for CVE-2022-21587 targeting Oracle E-Business Suite with file overwrite and shell creation capabilities.

exploitationpayload-generationpenetration-testing+2
153 years ago
weblogic-cve-2018-2628 preview

weblogic-cve-2018-2628

GitHubjiansiting/weblogic-cve-2018-2628

Python exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability. Provides remote code execution against unpatched…

exploitationexploit-frameworkspenetration-testing+2
148 years ago
CVE-2025-61882-Oracle-EBS preview

CVE-2025-61882-Oracle-EBS

GitHubzerozenxlabs/cve-2025-61882-oracle-ebs

Operational exploit for CVE-2025-61882 in Oracle E-Business Suite, with research artifacts for defensive validation, detection engineering, incident…

exploitationincident-responsepenetration-testing+2
191 year ago
Previous1…678…13Next