Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
SSRF-Testing preview

SSRF-Testing

GitHubcujanovic/ssrf-testing

SSRF (Server Side Request Forgery) testing resources

cloud-securitycurated-resourceseducation+6
2.5k
1 year ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
26 days ago
CVE-2026-66729-Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash preview

CVE-2026-66729-Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash

GitHubtheopaid/cve-2026-66729-out-of-bounds-read-in-facil.io-mime-parser-leads-to-server-crash

Security Advisory: Out-of-Bounds Read in facil.io MIME Parser leads to Server crash

binary-exploitationeducationpapers-research+2
26 days ago
React2Shell-Library preview

React2Shell-Library

GitHubwebsecuritylabs/react2shell-library

A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as…

curated-resourceseducationexploitation+6
77 months ago
chub-supply-chain-poc preview

chub-supply-chain-poc

GitHubmickmicksh/chub-supply-chain-poc

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

ai-securitycode-analysiseducation+5
45 months ago
React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web preview

React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web

GitHubadityabhatt3010/react2shell-cve-2025-55182-the-deserialization-bug-that-broke-the-web

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

ctfeducationexploitation+8
88 months ago
teamspeak3-vulnerabilities preview

teamspeak3-vulnerabilities

GitHubborn0monday/teamspeak3-vulnerabilities

Proof-of-concept exploits for CVE-2026-4390, CVE-2026-4391 and CVE-2026-4392 in TeamSpeak 3 server (3.13.7).

binary-exploitationeducationexploitation+2
2 months ago
CVE-2026-45806 preview

CVE-2026-45806

GitHub0xmrma/cve-2026-45806

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because…

educationexploitationpapers-research+3
1 month ago
CVE-2025-55182-React2Shell-RCE-POC preview

CVE-2025-55182-React2Shell-RCE-POC

GitHubrat5ak/cve-2025-55182-react2shell-rce-poc

This repository documents research into deserialization behavior within Next.js React Server Components (RSC) using the Flight protocol. It focuses…

code-analysiseducationexploitation+3
38 months ago
CVE-2026-35031 preview

CVE-2026-35031

GitHubkeraattin/cve-2026-35031

Critical path traversal to RCE vulnerability in Jellyfin Media Server (CVSS 9.9). Includes proof-of-concept exploit, technical analysis, and…

educationexploitationpapers-research+5
24 months ago
CVE-2025-56399 preview

CVE-2025-56399

GitHubtheethat-thamwasin/cve-2025-56399

An authenticated Remote Code Execution (RCE) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager…

educationexploitationpapers-research+3
39 months ago
CVE-2025-63419 preview

CVE-2025-63419

GitHubmmakingdom/cve-2025-63419

CrushFTP before 11.3.7_60 is vulnerable to HTML Injection. The Web-Based Server has a feature where users can share files, the feature reflects the…

educationpapers-researchvulnerability-analysis+2
28 months ago
conti-ransomware-writeup preview

conti-ransomware-writeup

GitHubjustjeff211/conti-ransomware-writeup

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

digital-forensicseducationforensics+6
4 months ago
CVE-2025-55182-analysis preview

CVE-2025-55182-analysis

GitHubairis101/cve-2025-55182-analysis

浅谈React Server Components RCE 漏洞分析

code-analysiseducationexploitation+3
15 months ago
React2ShellPoC preview

React2ShellPoC

GitHubgit0xlai/react2shellpoc

This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It…

educationexploitationpapers-research+3
7 months ago
TP-Link-TL-WR820N-CVE-2025-14175 preview

TP-Link-TL-WR820N-CVE-2025-14175

GitHubcybervinner/tp-link-tl-wr820n-cve-2025-14175

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

cryptographyeducationembedded-systems-security+3
7 months ago
CVE-2019-1068 preview

CVE-2019-1068

GitHubvulnerability-playground/cve-2019-1068

Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.

binary-exploitationeducationexploitation+3
4 years ago
MAL-012 preview

MAL-012

GitHubmbadanoiu/mal-012

MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server

exploitationpapers-researchpenetration-testing+3
1 year ago
Previous123Next