Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
CVE-2026-67279 preview

CVE-2026-67279

GitHubhackspeak/cve-2026-67279

Python proof-of-concept scripts for the MikroTrick MikroTik RouterOS SSH takeover chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) for…

authenticationembedded-systems-securityexploitation+7
3
2 days ago
CVE-2026-95675 preview

CVE-2026-95675

GitHubd6fault/cve-2026-95675

Python PoC exploiting CVE-2026-95675, an unauthenticated root command injection in D-Link DAP-1360 RevB firmware via a hardcoded auth-bypass and the…

embedded-systems-securityexploitationfirmware-analysis+6
14 days ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubalyaapm/cve-2025-55182-shellinteractive

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

command-and-controlexploitationpayload-generation+4
4 days ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubr3vpwnx/cve-2025-55182

Standalone exploit for CVE-2025-55182 achieving unauthenticated RCE in Next.js App Router via React Server Components Flight deserialization, with…

exploitationpayload-developmentpenetration-testing+3
20 days ago
CVE-2025-66478-PoC-Reverse-Shell preview

CVE-2025-66478-PoC-Reverse-Shell

GitHubjotaespig/cve-2025-66478-poc-reverse-shell

Proof-of-concept exploit for CVE-2025-55182/66478, a React Server Components deserialization RCE, delivering a reverse shell via crafted multipart…

exploitationpayload-developmentpenetration-testing+3
128 days ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
21 month ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubleast-significant-bit/cve-2025-55182

Remote code execution for React Server Components 19.0.0 - 19.2.0

exploitationpenetration-testingremote-access-tool+2
1 month ago
CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit preview

CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit

GitHubcerberusmrxi/cve-2025-55182-advanced-react-server-components-rce-exploit

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

data-exfiltrationexploitationpayload-development+6
11 month ago
hackEmbedded preview

hackEmbedded

GitHubdoudoudedi/hackembedded

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

command-and-controlembedded-systems-securityencryption-decryption-tools+8
2062 months ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubherick-costa/cve-2025-55182-react2shell-rce

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability in React Server Components via…

ctfeducationexploitation+5
13 months ago
React2Shell-PoC-CVE-2025-55182 preview

React2Shell-PoC-CVE-2025-55182

GitHublitndat/react2shell-poc-cve-2025-55182

PoC scanner and exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Detects vulnerable servers and executes remote…

educationexploitationlabs-practice+4
3 months ago
react2shell preview

react2shell

GitHubrvzsec/react2shell

react2shell - CVE-2025-55182 (Next.js: CVE-2025-66478) - Unauthenticated RCE in React Server Components (Flight Protocol) - PoC Exploit

exploitationpayload-generationpenetration-testing+3
3 months ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

ctfeducationexploitation+5
64 months ago
CVE-2026-38422 preview

CVE-2026-38422

GitHubsermikr0/cve-2026-38422

CVE-2026-38422 — Remote Code Execution via Combined Buffer Overflows in Tasmota fetch_jpg() (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+5
4 months ago
react2shell-poc preview

react2shell-poc

GitHubp3ta00/react2shell-poc

CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.

command-and-controleducationexploitation+5
94 months ago
react2shell-exploit preview

react2shell-exploit

GitHubyannisduvignau/react2shell-exploit

CVE-2025-55182, also known as React2Shell, is a critical vulnerability affecting Next.js applications using React Server Components (RSC) and Server…

educationexploitationpayload-development+3
4 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubdevianntsec/cve-2025-55182

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

educationexploitationexploit-frameworks+8
15 months ago
React2Shell_CVE-2025-55182 preview

React2Shell_CVE-2025-55182

GitHubyanoshercohen/react2shell_cve-2025-55182

React2Shell (CVE-2025-55182) Exploit

educationexploitationpayload-development+6
45 months ago
Previous12345Next