Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
CVE-2026-34835-Black-box-Analysis preview

CVE-2026-34835-Black-box-Analysis

GitHubcyber-note/cve-2026-34835-black-box-analysis

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

dns-analysiseducationpenetration-testing+3
6
1 month ago
Vehicle-Service-Management-System-User-List-Stored-Cross-Site-Scripting-XSS preview

Vehicle-Service-Management-System-User-List-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/vehicle-service-management-system-user-list-stored-cross-site-scripting-xss

CVE-2021-46073 - A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List…

educationexploitationpenetration-testing+3
3 months ago
sqlmc preview

sqlmc

GitHubmalvads/sqlmc

Official Kali Linux tool to check all urls of a domain for SQL injections :)

educationinformation-gatheringpenetration-testing+3
3813 months ago
CVE-2024-2997 preview

CVE-2024-2997

GitHub0xuho/cve-2024-2997

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

educationexploitationpenetration-testing+3
5 months ago
WAES preview

WAES

GitHubshiva108/waes

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

ctfeducationinformation-gathering+7
707 months ago
Open-Worldwide-Application-Security-Project-OWASP- preview

Open-Worldwide-Application-Security-Project-OWASP-

GitHubwaburig/open-worldwide-application-security-project-owasp-

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

educationpenetration-testingvulnerability-analysis+2
7 months ago
BWASP preview

BWASP

GitHubbwasp/bwasp

BoB Web Application Security Project

educationpenetration-testingvulnerability-analysis+3
2228 months ago
react2shell-scanner-rce-react-next-CVE-2025-55182-CVE-2025-66478 preview

react2shell-scanner-rce-react-next-CVE-2025-55182-CVE-2025-66478

GitHubsecurity-phoenix-demo/react2shell-scanner-rce-react-next-cve-2025-55182-cve-2025-66478

Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol…

code-analysiseducationexploitation+6
68 months ago
Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954- preview

Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-

GitHubshivanshkuntal/exploitation-of-a-remote-code-execution-vulnerability--cve-2024-7954-

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

educationexploitationinformation-gathering+8
18 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubl4rm4nd/cve-2025-55182

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

educationlabs-practicepenetration-testing+4
868 months ago
RscScan-cve-2025-55182 preview

RscScan-cve-2025-55182

GitHubveilvulp/rscscan-cve-2025-55182

RscScan: Professional cross-platform vulnerability scanner for Next.js Server Actions (CVE-2025-55182). Detects critical RCE flaws with…

educationexploitationpenetration-testing+3
38 months ago
http-react2shell preview

http-react2shell

GitHubmoisestapia/http-react2shell

Detection of the React Server Actions Exploit vector – CVE-2025-55182 / CVE-2025-66478

devsecopseducationexploitation+6
8 months ago
react2shell-detector preview

react2shell-detector

GitHubxiaopeng-ye/react2shell-detector

A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications

educationexploitationpenetration-testing+3
58 months ago
react2shell-checker preview

react2shell-checker

GitHubmuthaiyanmani/react2shell-checker

A security vulnerability scanner for detecting the React2Shell vulnerability (CVE-2025-55182) in Next.js and React applications.

educationinformation-gatheringreconnaissance+3
8 months ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubiteride/cve-2025-2294
educationexploitationpenetration-testing+3
11 months ago
ASST preview

ASST

GitHubowasp/asst

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

code-analysiseducationstatic-code-analysis+2
1891 year ago
CVE-2025-0054 preview

CVE-2025-0054

GitHubz3usx01/cve-2025-0054
educationpenetration-testingvulnerability-analysis+2
1 year ago
open-source-web-scanners preview

open-source-web-scanners

GitHubpsiinon/open-source-web-scanners

Curated list of open-source web security scanners, including general-purpose scanners, infrastructure scanners, and fuzzers, ordered by GitHub stars.

curated-resourceseducationfuzzing+3
1.6k1 year ago
Previous12Next