Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
215 results
CVE-2026-41940 preview

CVE-2026-41940

GitHubdennisec/cve-2026-41940

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

authentication-authorizationexploitationpenetration-testing+3
4 months ago
Automated-scanner-CVE-2026-41940 preview

Automated-scanner-CVE-2026-41940

GitHubsardine-web/automated-scanner-cve-2026-41940

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

authentication-authorizationcommand-and-controlexploitation+8
14 months ago
CVE-2025-55182_liyon preview

CVE-2025-55182_liyon

GitHubhujiaozhuzhu/cve-2025-55182_liyon

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

command-and-controleducationexploitation+7
5 months ago
R2SAE preview

R2SAE

GitHuboscar-mine/r2sae

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

command-and-controlexploitationpayload-generation+5
4 months ago
tanstack-compromise-checker preview

tanstack-compromise-checker

GitHubry-allan/tanstack-compromise-checker

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

command-and-controlforensicsincident-response+6
4 months ago
EpSiLoNPoInT- preview

EpSiLoNPoInT-

GitHubepsilonpoint88-glitch/epsilonpoint-

Modular exploit framework targeting CVE-2026-23550 in WordPress, featuring mass exploitation, obfuscation, post-exploitation, and Docker-based C2…

command-and-controlexploitationpayload-development+7
17 months ago
React2Shell preview

React2Shell

GitHubprowlsec/react2shell

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

command-and-controlexploitationpayload-generation+4
19 months ago
PHP_8.1.x_Exploit preview

PHP_8.1.x_Exploit

GitHubgl1tch0x1/php_8.1.x_exploit

Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)

command-and-controlcrawlerexploitation+7
15 months ago
SneeitScanner-CVE-2025-6389 preview

SneeitScanner-CVE-2025-6389

GitHubitsismarcos/sneeitscanner-cve-2025-6389

SneeitScanner - PoC & Scanner para RCE não autenticada no Sneeit Framework (CVE-2025-6389)

command-and-controlexploitationpayload-generation+3
19 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubatastycookie/cve-2025-55182

Python CLI exploit and scanner for CVE-2025-55182, a critical RCE in React Server Components, with command execution and nuclei-based detection.

command-and-controleducationexploitation+3
9 months ago
POC-CVE-2025-55182 preview

POC-CVE-2025-55182

GitHubdevvaibhav07/poc-cve-2025-55182

POC-CVE-2025-55182

command-and-controlexploitationpayload-generation+3
9 months ago
cve-2025-3248 preview

cve-2025-3248

GitHubbambooqj/cve-2025-3248

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

command-and-controlexploitationpenetration-testing+3
111 months ago
Mass-CVE-2025-29306 preview

Mass-CVE-2025-29306

GitHubmantanhacker/mass-cve-2025-29306

Mass Exploit for CVE-2025-29306

command-and-controlexploitationpenetration-testing+3
18 months ago
CVE-2025-55182-GUI preview

CVE-2025-55182-GUI

GitHubm3ngx1ng/cve-2025-55182-gui

CVE-2025-55182 漏洞检测与利用工具(GUI版)

command-and-controlexploitationpayload-development+5
18 months ago
auth-bypass-CVE-2025-40554 preview

auth-bypass-CVE-2025-40554

GitHubimbas007/auth-bypass-cve-2025-40554

Proof-of-concept exploit for CVE-2025-40554, an authentication bypass in SolarWinds Web Help Desk. Includes Nuclei template and Python exploit for…

authentication-authorizationexploitationpenetration-testing+3
18 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xsj/cve-2025-55182

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

command-and-controlexploitationpenetration-testing+3
17 months ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubaratane/cve-2024-9474

Palo Alto RCE Vuln

command-and-controlexploitationpenetration-testing+3
11 year ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubamitlttwo/cve-2022-1388

Python-based exploit for CVE-2022-1388, an F5 BIG-IP iControl REST authentication bypass leading to remote code execution. Supports single URL,…

command-and-controlexploitationpenetration-testing+3
13 years ago
Previous1…9101112Next