Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
208 results
R2SAE preview

R2SAE

GitHuboscar-mine/r2sae

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

command-and-controlexploitationpayload-generation+5
3 months ago
CVE-2024-46507 preview

CVE-2024-46507

GitHubsomchandra17/cve-2024-46507

build-script for CVE-2024-46507 and CVE-2024-46508

command-and-controleducationexploitation+6
11 year ago
blackbox-pentesting-infsecos preview

blackbox-pentesting-infsecos

GitHubsaqib-butt2/blackbox-pentesting-infsecos

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

command-and-controlctfexploitation+7
3 months ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubaratane/cve-2024-9474

Palo Alto RCE Vuln

command-and-controlexploitationpenetration-testing+3
11 year ago
CVE-2019-1653 preview

CVE-2019-1653

GitHubibrahimzx/cve-2019-1653

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…

command-and-controlexploitationinformation-gathering+3
13 years ago
Blackash-CVE-2025-33073 preview

Blackash-CVE-2025-33073

GitHubirjfifndn-prog/blackash-cve-2025-33073

CVE-2025-33073

command-and-controlexploitationlateral-movement+4
9 months ago
PoC-RCE-CVE-2025-55182 preview

PoC-RCE-CVE-2025-55182

GitHubilixm/poc-rce-cve-2025-55182

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

command-and-controlexploitationinformation-gathering+7
8 months ago
Audit-BlackBox-Web-to-Root preview

Audit-BlackBox-Web-to-Root

GitHubfbm31/audit-blackbox-web-to-root

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

command-and-controleducationexploitation+8
8 months ago
CVE-2025-55182-NextJS-Scanner-React2Shell-PoC preview

CVE-2025-55182-NextJS-Scanner-React2Shell-PoC

GitHubexrienz/cve-2025-55182-nextjs-scanner-react2shell-poc

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

command-and-controlexploitationpayload-generation+5
8 months ago
CVE-2025-55182-Simple-Scanner preview

CVE-2025-55182-Simple-Scanner

GitHubsatriarizka/cve-2025-55182-simple-scanner

High-fidelity RCE scanner for CVE-2025-55182 affecting Next.js RSC. Supports mass scanning, command execution, and automated recon pipelines. Built…

command-and-controleducationexploitation+5
8 months ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubth-secforge/cve-2024-10914

CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.

command-and-controleducationexploitation+4
11 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xsj/cve-2025-55182

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

command-and-controlexploitationpenetration-testing+3
16 months ago
Apache-Struts preview

Apache-Struts

GitHubc002/apache-struts

Python-based exploit for Apache Struts CVE-2017-5638 with single URL and batch scanning modes, vulnerability checking, and Nmap reconnaissance…

command-and-controlexploitationpenetration-testing+3
9 years ago
FiberBreak preview

FiberBreak

GitHubscumfrog/fiberbreak

React2Shell Exploitation Tool (CVE-2025-55182)

cloud-securitycommand-and-controldata-exfiltration+8
8 months ago
POC-CVE-2021-42013-EXPLOIT preview

POC-CVE-2021-42013-EXPLOIT

GitHubmakavellik/poc-cve-2021-42013-exploit

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

command-and-controlexploitationinformation-gathering+7
11 months ago
gardyn-hack preview

gardyn-hack

GitHubkristof-mattei/gardyn-hack

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

command-and-controlembedded-systems-securityexploitation+8
1 year ago
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
11 months ago
CVE-2022-22954-PoC preview

CVE-2022-22954-PoC

GitHubamit-pathak009/cve-2022-22954-poc

Proof-of-concept exploit for CVE-2022-22954, a VMware Workspace ONE Access and Identity Manager RCE via SSTI. Supports manual, file-based, and…

command-and-controlexploitationreconnaissance+2
4 years ago
Previous1…9101112Next