Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Labs & Practice | Kitploit
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k16h 38m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k16h 6m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
Bluekeep-Metasploit-Lab-Project preview

Bluekeep-Metasploit-Lab-Project

GitHubnweks/bluekeep-metasploit-lab-project

Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)

exploit-frameworksvulnerability-analysispenetration-testing+3
4 months ago
CVE-2021-46398 preview
Archived

CVE-2021-46398

GitHublaliea/cve-2021-46398

A Proof of Concept for the CVE-2021-46398 flaw exploitation

vulnerability-analysisexploitationweb-application-exploitation+3
2 years ago
CVE-2019-0232 preview

CVE-2019-0232

GitHubxsxtw/cve-2019-0232

Step-by-step lab environment for exploiting CVE-2019-0232, a Tomcat CGI command injection vulnerability, with setup instructions and payload examples.

vulnerability-analysisexploitationweb-application-exploitation+2
2 years ago
cve-2018-3811 preview

cve-2018-3811

GitHubcved-sources/cve-2018-3811

Docker container providing a vulnerable environment for CVE-2018-3811, designed for security testing and exploit practice within the Cved vulnerable…

vulnerability-scannerscontainer-securityvulnerability-analysis+3
5 years ago
Spring-Cloud-Function-SpEL preview

Spring-Cloud-Function-SpEL

GitHubpizz33/spring-cloud-function-spel

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

vulnerability-analysisexploitationweb-application-exploitation+2
244 years ago
PMAT-labs preview

PMAT-labs

GitHubhuskyhacks/pmat-labs

Labs for Practical Malware Analysis & Triage

reverse-engineeringforensicsmalware-analysis+3
1.1k5 months ago
CVE-2020-8840 preview

CVE-2020-8840

GitHubveraxy00/cve-2020-8840

Jackson-databind远程代码执行漏洞(CVE-2020-8840)分析复现环境代码

vulnerability-analysiscode-analysisexploitation+3
45 years ago
CVE-2024-21182 preview

CVE-2024-21182

GitHubdinosn/cve-2024-21182

Reproducible Docker lab for CVE-2024-21182 Oracle WebLogic T3/IIOP OpaqueReference JNDI injection leading to unauthenticated RCE. One-command…

vulnerability-analysisexploitationweb-application-exploitation+3
33 months ago
HyperOS-Directory-Traversal-Analysis preview

HyperOS-Directory-Traversal-Analysis

GitHubkkaanozturk/hyperos-directory-traversal-analysis

Xiaomi HyperOS AVCodec Medya Framework'ündeki Use-After-Free (CVE-2025-21082) Zafiyetinin Derinlemesine Analizi, Rust Simülasyonu ve İnteraktif Web…

static-analysisdynamic-analysis-sandboxingmemory-forensics+8
12 months ago
CVE-2023-44487 preview

CVE-2023-44487

GitHubhirokiii/cve-2023-44487

Educational environment for LTAT.04.022 Homework 4.

container-securityvulnerability-analysisconfiguration-auditing+4
3 months ago
CVE-2023-48223 preview

CVE-2023-48223

GitHublucastran05/cve-2023-48223

Proof-of-concept demonstrating JWT algorithm confusion in fast-jwt library. Includes vulnerable server, token forging script, and verification fix…

vulnerability-analysisexploitationweb-application-exploitation+3
5 months ago
ctf-tracker preview

ctf-tracker

GitHubxxdndxx/ctf-tracker

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

privilege-escalationreconnaissanceexploitation+6
22 days ago
the-book-of-secret-knowledge preview

the-book-of-secret-knowledge

GitHubtrimstray/the-book-of-secret-knowledge

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

osintweb-securitynetwork-security+8
237.8k1 year ago
hackaday-u preview

hackaday-u

GitHubwrongbaud/hackaday-u

Course materials for hackaday.io Ghidra training

static-analysisreverse-engineeringbinary-analysis+3
4402 years ago
pygoat preview

pygoat

GitHubadeyosemanputra/pygoat

intentionally vuln web Application Security in django

vulnerability-scannersweb-securitypenetration-testing+2
3395 months ago
lazyweb preview

lazyweb

GitHubramadhanamizudin/lazyweb

LazyWeb is a demonstration web application designed to showcase common server-side application vulnerabilities. Each vulnerability is categorized…

vulnerability-analysisweb-securitypenetration-testing+2
1281 year ago
scared preview

scared

GitHubeshard/scared

Python framework for performing side-channel analysis attacks (e.g., CPA) on public datasets, designed for educational use and hands-on practice in…

cryptographyeducationlabs-practice
1141 month ago
CVE-2025-55183_POC preview

CVE-2025-55183_POC

GitHubx-cotang/cve-2025-55183_poc

CVE-2025-55183 POC

vulnerability-analysisexploitationweb-application-exploitation+2
49 months ago
Previous1…345…100Next