Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
CVE-2026-1357-POC preview

CVE-2026-1357-POC

GitHubcybertechajju/cve-2026-1357-poc

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

data-exfiltrationexploitationpenetration-testing+5
9
7 months ago
CVE-2025-55182-poc-tool preview

CVE-2025-55182-poc-tool

GitHubdh4v4l8/cve-2025-55182-poc-tool

Automated exploit tool for CVE-2025-55182 in Next.js React Server Components. Enables remote command execution with built-in WAF bypass, custom…

exploitationpenetration-testingremote-access-tool+3
39 months ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
9 months ago
waf-bypass preview

waf-bypass

GitHubnemesida-waf/waf-bypass

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

api-security-testingpenetration-testingvulnerability-scanners+2
1.5k2 months ago
commix preview

commix

GitHubcommixproject/commix

Automated Αll-in-One OS command injection exploitation tool.

exploitationpenetration-testingvulnerability-scanners+2
5.9k1 day ago
HawkScan preview

HawkScan

GitHubc0dejump/hawkscan

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

crawlerfuzzinginformation-gathering+5
4633 years ago
react2shell-scanner preview

react2shell-scanner

GitHubalessiodos/react2shell-scanner

CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

exploitationpenetration-testingvulnerability-scanners+3
19 months ago
MeterPwrShell preview
Archived

MeterPwrShell

GitHubgetrektboy724/meterpwrshell

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

command-and-controlexploit-frameworksids-ips-evasion+7
2275 years ago
rschunter preview

rschunter

GitHubsumanrox/rschunter

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

command-and-controlexploitationpenetration-testing+3
379 months ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
5396 days ago
Atlas preview

Atlas

GitHubm4ll0k/atlas

Quick SQLMap Tamper Suggester

penetration-testingvulnerability-scannerswaf-bypass+1
1.4k5 years ago
WhatWaf preview

WhatWaf

GitHubekultek/whatwaf

Detect and bypass web application firewalls and protection systems

penetration-testingvulnerability-scannerswaf-bypass+1
2.9k2 years ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
353 days ago
Vxscan preview

Vxscan

GitHubal0ne/vxscan

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

crawlerinformation-gatheringosint+7
1.8k6 years ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.6k5 months ago
anubis-fetch preview

anubis-fetch

GitHubfzakaria/anubis-fetch

Like curl, but it gets past Anubis and Cloudflare bot-walls.

anti-botfingerprint-spoofingscripting-automation+3
3618 days ago
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.3k2 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubbhideki/cve-2026-87902

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

exploitationpayload-developmentpenetration-testing+6
3 days ago
Previous12Next