Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
81 results
cve-2025-55182-lab preview

cve-2025-55182-lab

GitHubabhaybansal16/cve-2025-55182-lab

Docker-based lab reproducing CVE-2025-55182 (React2Shell), an unauthenticated RCE in React Server Components Flight Protocol, with PoC exploit and…

container-securityeducationexploitation+6
8 days ago
CVE-2026-12944 preview

CVE-2026-12944

GitHubshadowforge-cyber/cve-2026-12944

Python PoC exploiting CVE-2026-12944, an SSRF in Langflow 1.10.0 via urllib in custom components, with authenticated read and fetch capabilities.

api-securityexploitationpenetration-testing+3
11 days ago
CVE-2026-13181-Telerik preview

CVE-2026-13181-Telerik

GitHubivanesk315/cve-2026-13181-telerik

Proof-of-concept exploit for CVE-2026-13181 affecting Telerik web components, demonstrating remote code execution via crafted requests.

exploitationpenetration-testingvulnerability-analysis+2
18 days ago
React2Shell-Scanner preview

React2Shell-Scanner

GitHubwi3memake/react2shell-scanner

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

api-security-testingdevsecopspenetration-testing+3
319 months ago
zyxel-wax650s-research-notebook-public preview

zyxel-wax650s-research-notebook-public

GitHubminanagehsalalma/zyxel-wax650s-research-notebook-public

Wiki-style research notebook for Zyxel WAX650S firmware emulation and vulnerability analysis

embedded-systems-securityfirmware-analysisreverse-engineering+2
15 months ago
CVE-2026-23869 preview

CVE-2026-23869

GitHubyohannslm/cve-2026-23869

Proof-of-concept exploit for CVE-2026-23869, a denial-of-service vulnerability in React Server Components allowing unauthenticated CPU exhaustion via…

exploitationvulnerability-analysisweb-application-exploitation+1
5 months ago
CVE-2026-23869-Exploit preview

CVE-2026-23869-Exploit

GitHubcybertechajju/cve-2026-23869-exploit

Automated exploit tool for CVE-2026-23869, a remote DoS in React Server Components. Includes PoC, Nuclei template, and scanning scripts for detection…

exploitationpenetration-testingreconnaissance+3
95 months ago
CVE-2023-24329-Exploit preview

CVE-2023-24329-Exploit

GitHubpentestmano/cve-2023-24329-exploit

Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
mitmproxy_rs preview

mitmproxy_rs

GitHubmitmproxy/mitmproxy_rs

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

api-security-testingmobile-app-pentestingnetwork-security+2
4471 month ago
cve-2025-55182-react2shell-analysis preview

cve-2025-55182-react2shell-analysis

GitHubaisha-jimoh/cve-2025-55182-react2shell-analysis

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

educationexploitationvulnerability-analysis+2
1 month ago
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityexploitationiot-security+5
11 month ago
epson-eh-tw5350-advisories preview

epson-eh-tw5350-advisories

GitHubdpfkdlemtp/epson-eh-tw5350-advisories

Security advisories for CVE-2021-43716/43717/43718 (Epson EH-TW5350)

authenticationembedded-systems-securityhardware-iot-security+2
1 month ago
HENlo preview

HENlo

GitHubtheofficialflow/henlo

WebKit+Kernel exploit chain for all PS Vita firmwares

binary-exploitationembedded-systems-securityexploitation+2
2383 years ago
react2shell-scanner preview

react2shell-scanner

GitHuborwagodfather/react2shell-scanner

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

exploitationpenetration-testingwaf-bypass+3
189 months ago
ufuzz preview

ufuzz

GitHubphikshun/ufuzz

Universal Plug and Fuzz

embedded-systems-securityfuzzingiot-security+3
417 years ago
CVE-2023-46003 preview

CVE-2023-46003

GitHubleekenghwa/cve-2023-46003

Proof-of-concept for a stored XSS vulnerability in i-doit Pro 25 and below, demonstrating payload injection via multiple parameters and components…

information-gatheringpenetration-testingvulnerability-analysis+2
2 years ago
React2shell-CVE-2025-55182-checker preview

React2shell-CVE-2025-55182-checker

GitHuboways/react2shell-cve-2025-55182-checker

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

code-analysisdevsecopssupply-chain-security+3
29 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsimantchaudhari/cve-2025-55182

Shell-based vulnerability scanner for CVE-2025-55182, a critical RCE in Next.js React Server Components. Designed for authorized penetration testing,…

educationexploitationpenetration-testing+3
9 months ago
Previous12345Next