Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
60 results
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
42
2 days ago
CVE-2026-78306 preview

CVE-2026-78306

GitHubwh02m1/cve-2026-78306

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and…

bluetooth-securityembedded-systems-securityexploitation+6
92 days ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubalyaapm/cve-2025-55182-shellinteractive

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

command-and-controlexploitationpayload-generation+4
4 days ago
Zhilly preview

Zhilly

GitLabsacriphanius/zhilly

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF…

embedded-systems-securityhardware-hackingiot-security+6
21 month ago
CVE-2025-71389_exploit preview

CVE-2025-71389_exploit

GitHub0xdak/cve-2025-71389_exploit

Python exploit for unauthenticated RCE in Cal.com (CVE-2025-71389) via React Server Components deserialization. Single request yields command…

educationexploitationpayload-generation+2
2 months ago
hackEmbedded preview

hackEmbedded

GitHubdoudoudedi/hackembedded

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

command-and-controlembedded-systems-securityencryption-decryption-tools+8
2062 months ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubherick-costa/cve-2025-55182-react2shell-rce

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability in React Server Components via…

ctfeducationexploitation+5
13 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubtheman001/cve-2025-55182

CVE-2025-55182 React RCE Test Program

educationexploitationlabs-practice+4
23 months ago
react2shell preview

react2shell

GitHubrvzsec/react2shell

react2shell - CVE-2025-55182 (Next.js: CVE-2025-66478) - Unauthenticated RCE in React Server Components (Flight Protocol) - PoC Exploit

exploitationpayload-generationpenetration-testing+3
3 months ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

ctfeducationexploitation+5
64 months ago
CVE-2025-66478-Research-Proof-of-Concept preview

CVE-2025-66478-Research-Proof-of-Concept

GitHubnilfredb/cve-2025-66478-research-proof-of-concept

Proof-of-concept exploit for CVE-2025-66478 targeting unsafe React Server Components payload handling in Next.js. Includes automated payload…

educationexploitationpapers-research+3
4 months ago
PoC-CVE-2025-55182 preview

PoC-CVE-2025-55182

GitHubluizhenz/poc-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182, a remote code execution vulnerability in React Server Components affecting React.js and Next.js.…

exploitationpayload-generationpenetration-testing+2
4 months ago
react2shell-poc preview

react2shell-poc

GitHubp3ta00/react2shell-poc

CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.

command-and-controleducationexploitation+5
94 months ago
routersploit preview

routersploit

GitHubthreat9/routersploit

Exploitation Framework for Embedded Devices

bluetooth-securityembedded-systems-securityexploitation+7
13.3k4 months ago
PoC-CVE-2025-55182 preview

PoC-CVE-2025-55182

GitHubmasterwok/poc-cve-2025-55182

CVE-2025-55182 (React2Shell) PoC: Unauthenticated RCE affecting React 19.x and Next.js < 15.1.4. Exploits vulnerabilities in the RSC Flight protocol.

educationexploitationpayload-generation+3
5 months ago
CVE-2025-55182_liyon preview

CVE-2025-55182_liyon

GitHubhujiaozhuzhu/cve-2025-55182_liyon

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

command-and-controleducationexploitation+7
5 months ago
reactshell preview

reactshell

GitHubh4r335hr/reactshell

Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)

exploitationpayload-generationpenetration-testing+2
7 months ago
react2shell-CVE-2025-55182 preview

react2shell-CVE-2025-55182

GitHubbrianlopezm99/react2shell-cve-2025-55182

An exploitation tool for the Next.js vulnerability CVE-2025-55182 that allows remote command execution through a poisoning prototype in React Server…

exploitationpayload-generationpenetration-testing+3
17 months ago
Previous1234Next