Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
Weblogic_Wsat_RCE preview

Weblogic_Wsat_RCE

GitHubkbsec/weblogic_wsat_rce

POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this…

educationexploitationpayload-development+3
4
7 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcyberleelawat/cve-2025-55182

A critical Remote Code Execution (RCE) vulnerability affecting the React Server Components (RSC) implementation within multiple packages including.

educationexploitationinformation-gathering+5
12 months ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubsaladin0x1/cve-2025-53770

Proof-of-concept exploit toolkit for SharePoint ToolPane RCE (CVE-2025-53770) with scanner, payload analysis, and multiple exploitation methods for…

authenticationeducationexploitation+5
41 year ago
CVE-2026-40487 preview

CVE-2026-40487

GitHubastaruf/cve-2026-40487

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

exploitationpayload-developmentpenetration-testing+3
34 months ago
cve-2016-1555 preview

cve-2016-1555

GitHubide0x90/cve-2016-1555

Metasploit module exploiting unauthenticated command injection in multiple Netgear router models to achieve remote code execution with root…

embedded-systems-securityexploitationexploit-frameworks+5
27 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcc3305/cve-2025-55182

Pre-authentication RCE exploit for React Server Components (CVE-2025-55182). Targets unsafe deserialization in react-server-dom packages across…

exploitationpayload-developmentpenetration-testing+2
3 months ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubthemalwareguardian/cve-2025-5548

Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.

binary-exploitationdebuggerseducation+7
15 months ago
CVE-2025-55182-poc preview

CVE-2025-55182-poc

GitHubducducuc111/cve-2025-55182-poc

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution via prototype chain vulnerability in React Server Components.…

code-analysisctfeducation+5
9 months ago
PoC-RCE-CVE-2025-55182 preview

PoC-RCE-CVE-2025-55182

GitHubilixm/poc-rce-cve-2025-55182

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

command-and-controlexploitationinformation-gathering+7
9 months ago
CVE-2010-5230 preview

CVE-2010-5230

GitHubotofoto/cve-2010-5230

Multiple untrusted search path vulnerabilities in MicroStation 7.1 allow local users to gain privileges via a Trojan horse (1) mptools.dll, (2)…

binary-exploitationexploitationpayload-development+2
5 years ago
SpookFlare preview
Archived

SpookFlare

GitHubhlldz/spookflare

Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.

exploit-frameworkspayload-developmentpayload-generation+1
9417 years ago
ProtectMyTooling preview

ProtectMyTooling

GitHubmgeeky/protectmytooling

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

binary-analysisexploit-frameworksioc-management+5
1.1k11 months ago
EmbedPayloadInPng preview

EmbedPayloadInPng

GitHubmaldev-academy/embedpayloadinpng

Embed a payload inside a PNG file

cryptographydata-exfiltrationids-ips-evasion+2
3731 year ago
Christmas preview

Christmas

GitHubmaldev-academy/christmas

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

adversarial-attackids-ips-evasionpayload-development+3
2592 years ago
CVE-2026-31431-CopyFail-Universal-LPE preview

CVE-2026-31431-CopyFail-Universal-LPE

GitHubshadowabi/cve-2026-31431-copyfail-universal-lpe

CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback

binary-exploitationcontainer-securityexploitation+6
584 months ago
PrestaShop-CVE-2018-19126 preview

PrestaShop-CVE-2018-19126

GitHubfarisv/prestashop-cve-2018-19126

PrestaShop (1.6.x <= 1.6.1.23 or 1.7.x <= 1.7.4.4) Back Office Remote Code Execution (CVE-2018-19126)

educationexploitationpayload-development+3
397 years ago
CVE-2025-8088-Multi-Document preview

CVE-2025-8088-Multi-Document

GitHubpentestfunctions/cve-2025-8088-multi-document

Exploit systems using older WinRAR without knowing their username (unlike other projects)

binary-exploitationeducationexploitation+4
351 year ago
R2C-CVE-2025-55182-66478 preview

R2C-CVE-2025-55182-66478

GitHubcybertechajju/r2c-cve-2025-55182-66478

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+8
249 months ago
Previous123Next