Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
48
17 days ago
wp2shell-poc-fulljs preview

wp2shell-poc-fulljs

GitHubraphy76/wp2shell-poc-fulljs

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

exploitationpayload-generationpenetration-testing+2
2 months ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

command-and-controlexploitationpayload-generation+5
52 months ago
agartha preview

agartha

GitHubvolkandindar/agartha

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

authentication-authorizationpayload-generationpenetration-testing+4
4124 months ago
CVE-2026-23830-SandBreak preview

CVE-2026-23830-SandBreak

GitHubgalaxy-sc/cve-2026-23830-sandbreak

Generates and delivers exploit payloads for CVE-2026-23830, a SandboxJS escape, with modes for blind OOB exfiltration and local calc PoC. Supports…

exploitationpayload-generationpenetration-testing+3
17 months ago
ReactNext2Shell preview

ReactNext2Shell

GitHubfurkankayapinar/reactnext2shell

CVE-2025-55182 and CVE-2025-66478

educationexploitationlabs-practice+5
19 months ago
CVE-2024-4367 preview

CVE-2024-4367

GitHub0xr2r/cve-2024-4367

Proof-of-concept for CVE-2024-4367 that generates a malicious PDF to exploit arbitrary JavaScript execution in PDF.js.

exploitationpayload-generationpenetration-testing+2
1 year ago
nodejsshell preview

nodejsshell

GitHubh3x0v3rl0rd/nodejsshell

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.

exploitationpayload-generationpenetration-testing+4
1 year ago
CVE-2024-8743-PoC preview

CVE-2024-8743-PoC

GitHubsiunam321/cve-2024-8743-poc

Proof-of-Concept script for WordPress plugin Bit File Manager version <= 6.5.7 Authenticated (Subscriber+) Limited JavaScript File Upload…

exploitationpayload-generationpenetration-testing+3
21 year ago
nodexp preview

nodexp

GitHubesmog/nodexp

NodeXP - A Server Side Javascript Injection tool capable of detecting and exploiting Node.js vulnerabilities

exploitationpayload-generationpenetration-testing+2
1071 year ago
toxssin preview

toxssin

GitHubt3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

exploitationinformation-gatheringpayload-generation+4
1.4k1 year ago
CVE-2024-39090-PoC preview

CVE-2024-39090-PoC

GitHubghostwirez/cve-2024-39090-poc

This PoC script exploits CVE-2024-39090, a CSRF to Stored XSS vulnerability in PHPGurukul Online Shopping Portal v2.0. It automates CSRF attacks to…

exploitationpayload-generationpenetration-testing+1
1 year ago
CVE-2024-43160 preview

CVE-2024-43160

GitHubktn1990/cve-2024-43160

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is…

exploitationpayload-generationpenetration-testing+3
22 years ago
CVE-2024-21683-RCE preview

CVE-2024-21683-RCE

GitHubphucrio/cve-2024-21683-rce

Proof-of-concept exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence. Executes a JavaScript payload against…

exploitationpayload-generationpenetration-testing+2
12 years ago
CVE-2023-44758_GDidees-CMS-Stored-XSS---Title preview

CVE-2023-44758_GDidees-CMS-Stored-XSS---Title

GitHubsromanhu/cve-2023-44758_gdidees-cms-stored-xss---title

GDidees CMS 3.9.2 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to…

exploitationpayload-generationpenetration-testing+3
3 years ago
JSshell preview

JSshell

GitHubshelld3v/jsshell

JSshell - JavaScript reverse/remote shell

payload-generationpenetration-testingremote-access-tool+1
6333 years ago
CVE-2018-0114 preview

CVE-2018-0114

GitHubj4k0m/cve-2018-0114

Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.

cryptographyexploitationpayload-generation+3
45 years ago
burpsuite-copy-as-xmlhttprequest preview

burpsuite-copy-as-xmlhttprequest

GitHubvulnbe/burpsuite-copy-as-xmlhttprequest

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

payload-generationpenetration-testingweb-application-exploitation
335 years ago
Previous12Next