Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
React2Shell preview

React2Shell

GitHubphanhoangkhang/react2shell

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

dynamic-analysis-sandboxingeducationexploitation+6
7 days ago
http-request-smuggler preview

http-request-smuggler

GitHubportswigger/http-request-smuggler
dynamic-analysis-sandboxingpenetration-testingvulnerability-scanners+3
1.2k11 days ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
627 days ago
fastjson-jsontype-rce-lab preview

fastjson-jsontype-rce-lab

GitHubdinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

dynamic-analysis-sandboxingeducationexploitation+5
20528 days ago
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
15 months ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubthemalwareguardian/cve-2017-14980

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can…

binary-exploitationdebuggerseducation+7
15 months ago
AWE preview

AWE

GitHubstuxlabs/awe

adaptive agents for dynamic web penetration testing

dynamic-analysis-sandboxingeducationpapers-research+4
215 months ago
yaml-payload preview

yaml-payload

GitHubseal-sec-demo-2/yaml-payload

SnakeYAML CVE-2022-1471 exploit payload for demo

dynamic-analysis-sandboxingeducationexploitation+3
6 months ago
burpfox preview

burpfox

GitHubhalilkirazkaya/burpfox

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

dynamic-analysis-sandboxingpenetration-testingvulnerability-analysis+3
236 months ago
react2shell_analyzer preview

react2shell_analyzer

GitHubbenrich127n/react2shell_analyzer

a dart package to analyze CVE-2025-55182 react2shell

dynamic-analysis-sandboxingpenetration-testingvulnerability-analysis+3
18 months ago
CVE-2019-18935 preview

CVE-2019-18935

GitHubalanbarret/cve-2019-18935
dynamic-analysis-sandboxingeducationexploitation+4
18 months ago
CVE-2025-55182-react2shell preview

CVE-2025-55182-react2shell

GitHubaastikgakhar/cve-2025-55182-react2shell

Detects exposed React Server Components vulnerable to CVE-2025-55182 via RSC negotiation.

dynamic-analysis-sandboxingexploitationpenetration-testing+3
8 months ago
Next.js-RSC-RCE-Scanner-Burp-Suite-Extension preview

Next.js-RSC-RCE-Scanner-Burp-Suite-Extension

GitHubtobiasguta/next.js-rsc-rce-scanner-burp-suite-extension

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

dynamic-analysis-sandboxingexploitationpenetration-testing+3
248 months ago
cve-2017-9822 preview

cve-2017-9822

GitHubtnot123/cve-2017-9822
binary-exploitationcode-analysisdebuggers+8
10 months ago
analyze-Exploit-CVE-2023-22518-Confluence preview

analyze-Exploit-CVE-2023-22518-Confluence

GitHubd3ckkno0b/analyze-exploit-cve-2023-22518-confluence
code-analysisdebuggerseducation+4
11 year ago
Spring-Boot-Tomcat-CVE-2025-24813 preview

Spring-Boot-Tomcat-CVE-2025-24813

GitHubn0n-zer0/spring-boot-tomcat-cve-2025-24813

POC for CVE-2025-24813 using Spring-Boot

dynamic-analysis-sandboxingexploitationpayload-development+3
1 year ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubcharis3306/cve-2025-24813

CVE-2025-24813利用工具

dynamic-analysis-sandboxingexploitationpayload-development+3
161 year ago
Text4shell--Automated-exploit---CVE-2022-42889 preview

Text4shell--Automated-exploit---CVE-2022-42889

GitHubadarshpv9746/text4shell--automated-exploit---cve-2022-42889
dynamic-analysis-sandboxingexploitationpayload-development+3
3 years ago
Previous12Next