Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
60 results
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
42
2 days ago
CVE-2026-78306 preview

CVE-2026-78306

GitHubwh02m1/cve-2026-78306

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and…

bluetooth-securityembedded-systems-securityexploitation+6
92 days ago
IntelTXE-PoC preview

IntelTXE-PoC

GitHubxenokovah/inteltxe-poc

Intel Management Engine JTAG Proof of Concept - 2022 Instructions

binary-analysisbinary-exploitationembedded-systems-security+5
324 years ago
lrs-pager-systems-bruteforce preview

lrs-pager-systems-bruteforce

GitHubjimilinuxguy/lrs-pager-systems-bruteforce

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

embedded-systems-securityexploitationhardware-hacking+4
523 years ago
CVE-2025-71389_exploit preview

CVE-2025-71389_exploit

GitHub0xdak/cve-2025-71389_exploit

Python exploit for unauthenticated RCE in Cal.com (CVE-2025-71389) via React Server Components deserialization. Single request yields command…

educationexploitationpayload-generation+2
2 months ago
Zhilly preview

Zhilly

GitLabsacriphanius/zhilly

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF…

embedded-systems-securityhardware-hackingiot-security+6
21 month ago
React2P4IM0Nshell preview

React2P4IM0Nshell

GitHubmammaninelsond/react2p4im0nshell

💥Extension Tool para Auditoría y Explotación avanzada RCE/Source Leak/Dos (CVE-2025-55182/83/84) para entornos Next.js y React Server Components…

educationexploit-frameworksinformation-gathering+6
39 months ago
CVE-2025-55182POC preview

CVE-2025-55182POC

GitHubsudo-yangziran/cve-2025-55182poc

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution in React Server Components via malicious ACTION payloads and…

exploitationpayload-generationpenetration-testing+2
29 months ago
uC_mousejack preview

uC_mousejack

GitHubinsecurityofthings/uc_mousejack

Mousejack for ATmega32u4

bluetooth-securityembedded-systems-securityhardware-hacking+4
2579 years ago
CVE-2024-29671-POC preview

CVE-2024-29671-POC

GitHublaskdjlaskdj12/cve-2024-29671-poc

This is POC of CVE-2024-29671

binary-exploitationembedded-systems-securityexploitation+7
11 year ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubmarcourbano/cve-2021-44228

PoC for CVE-2021-44228.

educationexploitationlabs-practice+3
74 years ago
CVE-2025-55182-React2Shell preview

CVE-2025-55182-React2Shell

GitHubrsch-io/cve-2025-55182-react2shell

React2Shell (CVE-2025-55182) proof-of-concept (PoC) exploit demonstrating a CRITICAL remote code execution (RCE) vulnerability in modern web…

educationexploitationpayload-generation+4
19 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubzzhorc/cve-2025-55182

CVE-2025-55182复现环境及RCE回显poc

exploitationpayload-generationpenetration-testing+4
89 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubxiaolvchen/cve-2025-55182

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)

exploitationpayload-generationpenetration-testing+3
18 months ago
CVE-2021-41730 preview

CVE-2021-41730

GitHubyezeting/cve-2021-41730

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

command-and-controlembedded-systems-securityexploitation+5
4 years ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

ctfeducationexploitation+5
64 months ago
react2shell-poc preview

react2shell-poc

GitHubp3ta00/react2shell-poc

CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.

command-and-controleducationexploitation+5
94 months ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubrajchowdhury240/react2shell-cve-2025-55182

React2Shell | CVE-2025-55182 - React Server Components RCE

exploitationpayload-generationpenetration-testing+2
9 months ago
Previous1234Next