Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
React2Shell preview

React2Shell

GitHubphanhoangkhang/react2shell

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

dynamic-analysis-sandboxingeducationexploitation+6
7 days ago
analyze-Exploit-CVE-2023-22518-Confluence preview

analyze-Exploit-CVE-2023-22518-Confluence

GitHubd3ckkno0b/analyze-exploit-cve-2023-22518-confluence
code-analysisdebuggerseducation+4
11 year ago
CollaboratorPlusPlus preview

CollaboratorPlusPlus

GitHubnccgroup/collaboratorplusplus
dynamic-analysis-sandboxingencryption-decryption-toolspenetration-testing+3
1474 years ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
627 days ago
fastjson-jsontype-rce-lab preview

fastjson-jsontype-rce-lab

GitHubdinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

dynamic-analysis-sandboxingeducationexploitation+5
20528 days ago
AWE preview

AWE

GitHubstuxlabs/awe

adaptive agents for dynamic web penetration testing

dynamic-analysis-sandboxingeducationpapers-research+4
215 months ago
cve-2019-14540-exploit preview

cve-2019-14540-exploit

GitHubleadroyal/cve-2019-14540-exploit

CVE-2019-14540 Exploit

dynamic-analysis-sandboxingexploitationpayload-generation+2
217 years ago
bradamsa preview

bradamsa

GitHubikkisoft/bradamsa

Burp Suite extension to generate Intruder payloads using Radamsa

dynamic-analysis-sandboxingfuzzingpayload-generation+3
918 years ago
log4j-Scan-Burpsuite preview

log4j-Scan-Burpsuite

GitHubsnow0715/log4j-scan-burpsuite

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

dynamic-analysis-sandboxingexploitationpenetration-testing+3
134 years ago
jndi-ldap-test-server preview

jndi-ldap-test-server

GitHubrakutentech/jndi-ldap-test-server

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

dynamic-analysis-sandboxingexploitationinformation-gathering+3
114 years ago
Next.js-RSC-RCE-Scanner-Burp-Suite-Extension preview

Next.js-RSC-RCE-Scanner-Burp-Suite-Extension

GitHubtobiasguta/next.js-rsc-rce-scanner-burp-suite-extension

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

dynamic-analysis-sandboxingexploitationpenetration-testing+3
248 months ago
yaml-payload preview

yaml-payload

GitHubseal-sec-demo-2/yaml-payload

SnakeYAML CVE-2022-1471 exploit payload for demo

dynamic-analysis-sandboxingeducationexploitation+3
6 months ago
Spring-Boot-Tomcat-CVE-2025-24813 preview

Spring-Boot-Tomcat-CVE-2025-24813

GitHubn0n-zer0/spring-boot-tomcat-cve-2025-24813

POC for CVE-2025-24813 using Spring-Boot

dynamic-analysis-sandboxingexploitationpayload-development+3
1 year ago
CVE-2019-11043_env preview

CVE-2019-11043_env

GitHubmoniik/cve-2019-11043_env

remote debug environment for CLion

debuggerseducationexploitation+2
16 years ago
CVE-2012-1889 preview

CVE-2012-1889

GitHubwhu-enjoy/cve-2012-1889

这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件

debuggerseducationexploitation+4
39 years ago
Burp-Log4j-HammerTime preview

Burp-Log4j-HammerTime

GitHubdxc-strikeforce/burp-log4j-hammertime

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046

dynamic-analysis-sandboxingexploitationpenetration-testing+3
84 years ago
CVE-2014-4140 preview

CVE-2014-4140

GitHubday6reak/cve-2014-4140
binary-exploitationdebuggersexploitation+3
11 years ago
CVE-2014-4109 preview

CVE-2014-4109

GitHubday6reak/cve-2014-4109
binary-exploitationdebuggersexploitation+2
11 years ago
Previous12Next