Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
CVE-2024-3640_WafBypass preview

CVE-2024-3640_WafBypass

GitHubh1ng007/cve-2024-3640_wafbypass

Exploit tool for CVE-2024-3640 that bypasses WAF using XML comment injection to achieve command execution and custom memory shell deployment.

exploitationpayload-generationpenetration-testing+3
3
1 year ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
8 months ago
react2shell-scanner preview

react2shell-scanner

GitHubassetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

exploitationpayload-generationpenetration-testing+3
2.5k8 months ago
XSS-LOADER preview

XSS-LOADER

GitHubcapture0x/xss-loader

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

payload-generationpenetration-testingwaf-bypass+2
6223 months ago
recollapse preview

recollapse

GitHub0xacb/recollapse

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

fuzzingpayload-generationwaf-bypass+1
1.4k1 year ago
sqlmap-ai preview

sqlmap-ai

GitHubatiilla/sqlmap-ai

This script automates SQL injection testing using SQLMap with AI-powered decision making.

payload-generationpenetration-testingvulnerability-scanners+3
4456 months ago
XSSFuzzer preview

XSSFuzzer

GitHubnytrorst/xssfuzzer

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

fuzzingpayload-generationwaf-bypass+1
1387 years ago
react2shell-ultimate preview

react2shell-ultimate

GitHubhackersatyamrastogi/react2shell-ultimate

Multi-mode vulnerability scanner for CVE-2025-66478 (Next.js RSC RCE) with WAF bypass, interactive shell, batch scanning, and JSON automation output…

command-and-controlexploitationpayload-generation+4
1528 months ago
nmap-log4shell preview

nmap-log4shell

GitHubgiterlizzi/nmap-log4shell

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

exploitationnetwork-securitypayload-generation+4
794 years ago
XSSYA preview

XSSYA

GitHubyehia-mamdouh/xssya

Automated XSS scanner with vulnerability confirmation, WAF bypass via encoded payloads, and cookie extraction for penetration testing of web…

payload-generationpenetration-testingvulnerability-analysis+3
973 years ago
React2Shell preview

React2Shell

GitHubxalgord/react2shell

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

command-and-controlexploitationpayload-generation+6
528 months ago
php-cgi-Injector preview

php-cgi-Injector

GitHubnight-have-dreams/php-cgi-injector

Automated PHP-CGI parameter injection exploit tool targeting CVE-2024-4577 and CVE-2024-8926. Supports command execution, file upload/download, WAF…

command-and-controlexploitationpayload-generation+4
521 year ago
Log4Shell-obfuscated-payloads-generator preview

Log4Shell-obfuscated-payloads-generator

GitHubr3kind1e/log4shell-obfuscated-payloads-generator

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

exploitationpayload-generationpenetration-testing+3
254 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubroxas-tan/cve-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating JNDI injection-based remote code execution against vulnerable Log4j versions,…

exploitationpayload-generationremote-access-tool+3
104 years ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Graphical RCE exploit tool for CVE-2025-55182 in Next.js RSC. Supports remote command execution, arbitrary JS execution, file read/write, directory…

command-and-controlexploitationpayload-generation+5
51 month ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubzzhorc/cve-2025-55182

Scanner for CVE-2025-55182 RCE in Next.js/React apps. Detects vulnerability via multipart PoC, supports safe side-channel mode, WAF bypass, and…

exploitationpayload-generationpenetration-testing+4
88 months ago
log4j-shell-csw preview

log4j-shell-csw

GitHubcybersecurityworks553/log4j-shell-csw

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

command-and-controlexploitationpayload-generation+3
84 years ago
Log4Shell preview

Log4Shell

GitHubr00thunter/log4shell

Generic Scanner for Apache log4j RCE CVE-2021-44228

exploitationfuzzingpayload-generation+3
74 years ago
Previous12Next