Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
88 results
CVE-2022-22965-Spring-Core-Rce preview

CVE-2022-22965-Spring-Core-Rce

GitHubtangxiaofeng7/cve-2022-22965-spring-core-rce

批量无损检测CVE-2022-22965

container-securitydynamic-analysis-sandboxingexploitation+3
39
4 years ago
AWE preview

AWE

GitHubstuxlabs/awe

adaptive agents for dynamic web penetration testing

dynamic-analysis-sandboxingeducationpapers-research+4
216 months ago
not-slithering-anywhere preview

not-slithering-anywhere

GitHubtrailofbits/not-slithering-anywhere

The Python Version of our Not Go-ing Anywhere Vulnerable Application

dynamic-analysis-sandboxingeducationlabs-practice+3
112 years ago
jndi-ldap-test-server preview

jndi-ldap-test-server

GitHubrakutentech/jndi-ldap-test-server

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

dynamic-analysis-sandboxingexploitationinformation-gathering+3
114 years ago
sparkplugFuzzer preview

sparkplugFuzzer

GitHubbishopfox/sparkplugfuzzer

Fuzzer for the Sparkplug B IIoT protocol

authenticationdynamic-analysis-sandboxingfuzzing+5
22 months ago
CVE-2026-53753-Crawl4AI-RCE preview

CVE-2026-53753-Crawl4AI-RCE

GitHubbiitts/cve-2026-53753-crawl4ai-rce

CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.

code-analysisdynamic-analysis-sandboxingeducation+7
2 months ago
frida-stalker-NtStrace preview

frida-stalker-NtStrace

GitHubgmh5225/frida-stalker-ntstrace

frida-stalker based system call tracer on windows(x64).

binary-analysisdebuggersdynamic-analysis-sandboxing+4
33 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubycseo-git/cve-2025-55182

a.k.a. React2Shell

code-analysiscontainer-securityctf+7
4 months ago
markdown-exfil-tester preview

markdown-exfil-tester

GitHubtrerb/markdown-exfil-tester

Black-box test whether an LLM chatbot is vulnerable to markdown/HTML exfil (CVE-2025-32711 class). Spins up a sink, sends payloads, renders in…

ai-securityctfdynamic-analysis-sandboxing+6
5 months ago
CVE-2025-55182-react2shell preview

CVE-2025-55182-react2shell

GitHubaastikgakhar/cve-2025-55182-react2shell

Detects exposed React Server Components vulnerable to CVE-2025-55182 via RSC negotiation.

dynamic-analysis-sandboxingexploitationpenetration-testing+3
10 months ago
CollaboratorPlusPlus preview

CollaboratorPlusPlus

GitHubnccgroup/collaboratorplusplus

Burp Suite extension enhancing Collaborator with context capture, polling history, and optional AES-encrypted authentication for private server…

dynamic-analysis-sandboxingencryption-decryption-toolspenetration-testing+3
1484 years ago
react2shell preview

react2shell

GitHubfreeqaz/react2shell

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

code-analysisdynamic-analysis-sandboxingeducation+6
6910 months ago
CaptainHook preview

CaptainHook

GitHubsynacktiv/captainhook

Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

binary-analysiscode-analysisdebuggers+2
94 years ago
the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss preview

the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

GitHubhunt-benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

android-securitydynamic-analysis-sandboxingexploitation+6
23 days ago
CVE-2020-6514 preview

CVE-2020-6514

GitHubhasan-khalil/cve-2020-6514

Exploit for CVE-2020-6514 targeting WebRTC SCTP memory corruption in Android applications. Uses Frida to hook native functions and alter SCTP packets…

android-securitybinary-exploitationdynamic-analysis-sandboxing+4
26 years ago
CVE-2026-34197 preview

CVE-2026-34197

GitHublat-06/cve-2026-34197

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

code-analysisdynamic-analysis-sandboxingeducation+5
4 months ago
CVE-2021-44228_Example preview

CVE-2021-44228_Example

GitHubchilliwebs/cve-2021-44228_example

Docker-based reproduction environment for CVE-2021-44228 (Log4Shell) with marshalsec LDAP server, exploit web server, and vulnerable Java application…

dynamic-analysis-sandboxingexploitationpayload-generation+2
14 years ago
Text4shell--Automated-exploit---CVE-2022-42889 preview

Text4shell--Automated-exploit---CVE-2022-42889

GitHubadarshpv9746/text4shell--automated-exploit---cve-2022-42889

Automated exploit for CVE-2022-42889 (Text4Shell) with a vulnerable Dockerized app for testing and manual exploitation guidance.

dynamic-analysis-sandboxingexploitationpayload-development+3
3 years ago
Previous12345Next