Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
618 results
CVE-2026-12960 preview

CVE-2026-12960

GitHubl0lsec/cve-2026-12960

CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor…

android-securityexploitationmobile-app-pentesting+3
2 months ago
cve-2025-55182-scanner preview

cve-2025-55182-scanner

GitHubxkillbit/cve-2025-55182-scanner

Passive vulnerability scanner for CVE-2025-55182 and CVE-2025-66478, detecting unauthenticated RCE in React Server Components via framework…

exploitationinformation-gatheringpenetration-testing+3
49 months ago
React-2-Shell preview

React-2-Shell

GitHubasadahmad-1337/react-2-shell

This is a security exploit tool targeting CVE-2025-55182. It exploits a Remote Code Execution (RCE) vulnerability in React Server Components

exploitationpayload-generationpenetration-testing+3
48 months ago
CVE-2025-71389_exploit preview

CVE-2025-71389_exploit

GitHub0xdak/cve-2025-71389_exploit

Python exploit for unauthenticated RCE in Cal.com (CVE-2025-71389) via React Server Components deserialization. Single request yields command…

educationexploitationpayload-generation+2
2 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubleast-significant-bit/cve-2025-55182

Remote code execution for React Server Components 19.0.0 - 19.2.0

exploitationpenetration-testingremote-access-tool+2
1 month ago
React2Shell-PoC-CVE-2025-55182 preview

React2Shell-PoC-CVE-2025-55182

GitHublitndat/react2shell-poc-cve-2025-55182

PoC scanner and exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Detects vulnerable servers and executes remote…

educationexploitationlabs-practice+4
3 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcyberleelawat/cve-2025-55182

A critical Remote Code Execution (RCE) vulnerability affecting the React Server Components (RSC) implementation within multiple packages including.

educationexploitationinformation-gathering+5
13 months ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubalyaapm/cve-2025-55182-shellinteractive

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

command-and-controlexploitationpayload-generation+4
4 days ago
react2shell-CVE-2025-55182-poc preview

react2shell-CVE-2025-55182-poc

GitHubjoelvaiju/react2shell-cve-2025-55182-poc

Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing.

exploitationpayload-developmentpenetration-testing+3
39 months ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubspeatx/react2shell-cve-2025-55182

CVE-2025-55182 — Unauthenticated RCE in React Server Components (React2Shell). CVSS 10.0 exploit tool for authorized penetration testing.

command-and-controleducationexploitation+5
24 months ago
CVE-2026-39253-Advisory preview

CVE-2026-39253-Advisory

GitHubtimtimxs/cve-2026-39253-advisory

Public advisory for CVE-2026-39253, addressing an insecure deserialisation in Pivotal CRM 6.6.04.08 allowing remote code execution via unsafe…

educationexploitationpapers-research+2
2 months ago
CVE-2025-55182-Exploit-PoC-Scanner preview

CVE-2025-55182-Exploit-PoC-Scanner

GitHubzemarkhos/cve-2025-55182-exploit-poc-scanner

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and…

command-and-controldynamic-analysis-sandboxingeducation+7
29 months ago
react2shell-scanner preview

react2shell-scanner

GitHubnxgn-kd01/react2shell-scanner

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

code-analysisdevsecopsexploitation+3
38 months ago
CVE-2025-55182-React2Shell-RCE-POC preview

CVE-2025-55182-React2Shell-RCE-POC

GitHubrat5ak/cve-2025-55182-react2shell-rce-poc

This repository documents research into deserialization behavior within Next.js React Server Components (RSC) using the Flight protocol. It focuses…

code-analysiseducationexploitation+3
29 months ago
CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit preview

CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit

GitHubcerberusmrxi/cve-2025-55182-advanced-react-server-components-rce-exploit

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

data-exfiltrationexploitationpayload-development+6
11 month ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubsyrins/cve-2025-55182-react2shell-rce

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

command-and-controleducationexploitation+4
39 months ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubherick-costa/cve-2025-55182-react2shell-rce

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability in React Server Components via…

ctfeducationexploitation+5
13 months ago
CVE-2026-22010-Android-Intent-Redirection-to-Exported-Component preview

CVE-2026-22010-Android-Intent-Redirection-to-Exported-Component

GitHubgeorge0papasotiriou/cve-2026-22010-android-intent-redirection-to-exported-component

Proof-of-concept for CVE-2026-22010 Android intent redirection: demonstrates an exported activity forwarding intents to attacker-controlled internal…

android-securityeducationexploitation+3
11 month ago
Previous1…345…35Next