Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k16h 38m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k16h 6m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
PoC-CVE-2019-10743 preview

PoC-CVE-2019-10743

GitHubalbisorua/poc-cve-2019-10743

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubahmedshamsddin/cve-2025-55182

Python exploit for CVE-2025-55182 in React Server Components, injecting a shell into Next.js 16.0.6 applications. Includes a vulnerable app for…

payload-generationvulnerability-analysisexploitation+3
9 months ago
trust-boundary-ctf preview

trust-boundary-ctf

GitHubacseguin21/trust-boundary-ctf

Browser-based MCP CTF — OAuth token confusion and session isolation failure (CVE-2025-49596 pattern). DevTools only.

vulnerability-analysisweb-securityctf+3
5 months ago
CVE-2025-8671 preview

CVE-2025-8671

GitHubabiyeenzo/cve-2025-8671

PoC éducatif pour la vulnérabilité CVE-2025-8671 (DoS HTTP/2 sur lighttpd). À utiliser uniquement en laboratoire local.

vulnerability-analysisexploitationweb-security+2
1 year ago
cdt-vulnsamba-deploy preview

cdt-vulnsamba-deploy

GitHubzanex360/cdt-vulnsamba-deploy

CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box

vulnerability-analysisexploitationpenetration-testing+3
7 months ago
CVE-2025-64459 preview

CVE-2025-64459

GitHubz3yr0xx/cve-2025-64459

CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment…

vulnerability-analysisweb-application-exploitationweb-security+3
9 months ago
LOGJ4_PocShell_CVE-2021-44228 preview

LOGJ4_PocShell_CVE-2021-44228

GitHubyanghyperdata/logj4_pocshell_cve-2021-44228

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

payload-generationvulnerability-analysisexploitation+3
2 years ago
5MMISSI-CVE-2017-1000499 preview

5MMISSI-CVE-2017-1000499

GitHubvillaquiranm/5mmissi-cve-2017-1000499

Proof-of-concept exploit for CVE-2017-1000499, a CSRF vulnerability in phpMyAdmin, demonstrating harmful database operations via crafted URLs.

vulnerability-analysisexploitationweb-application-exploitation+2
7 years ago
CVE-2023-3460_FIX preview

CVE-2023-3460_FIX

GitHubtrankubao/cve-2023-3460_fix

Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))

privilege-escalationvulnerability-analysisexploitation+2
11 months ago
HTTP-2-RapidReset-CVE-2023-44487-Testlab preview

HTTP-2-RapidReset-CVE-2023-44487-Testlab

GitHubtlevente20/http-2-rapidreset-cve-2023-44487-testlab

Docker lab for reproducing and studying CVE-2023-44487 (HTTP/2 Rapid Reset) for thesis research, providing a controlled environment for vulnerability…

vulnerability-analysisexploitationweb-security+2
2 months ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubshubhankargupta691/cve-2024-42009

Nuclei templates and Docker lab to demonstrate and validate CVE-2024-42009, a reflected XSS in Roundcube Webmail, using Out-of-Band detection via…

vulnerability-analysisexploitationweb-application-exploitation+3
11 months ago
CyberSec2026 preview

CyberSec2026

GitHubsanderschepers1993/cybersec2026

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

vulnerability-analysisexploitationweb-application-exploitation+3
3 months ago
Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow preview

Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow

GitHubsamuel-g3/escalamiento-de-privilegios-usando-el-kernel-exploit-dirty-cow

Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones…

privilege-escalationvulnerability-analysisexploitation+3
1 year ago
lab-SMB-responder-CVE-2024-21413 preview

lab-SMB-responder-CVE-2024-21413

GitHubsallocinavalcante/lab-smb-responder-cve-2024-21413

Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).

password-crackingvulnerability-analysisexploitation+5
7 months ago
CVE-2025-41243-Vulnerability-Lab preview

CVE-2025-41243-Vulnerability-Lab

GitHubsfn233/cve-2025-41243-vulnerability-lab

Spring Cloud Gateway SpEL RCE Vulnerability Environment

container-securityvulnerability-analysisexploitation+3
7 months ago
CVE-2019-16784-POC preview

CVE-2019-16784-POC

GitHubckrielle/cve-2019-16784-poc

A Proof of Concept exploit for the PyInstaller CVE-2019-16783

privilege-escalationvulnerability-analysisexploitation+4
2 years ago
EthernalBlue_report preview

EthernalBlue_report

GitHubcedric-martz/ethernalblue_report

This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).

vulnerability-analysisexploitationctf+4
1 year ago
CVE-2026-49468-LiteLLM-Auth-Bypass preview

CVE-2026-49468-LiteLLM-Auth-Bypass

GitHubbiitts/cve-2026-49468-litellm-auth-bypass

CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.

vulnerability-analysisexploitationweb-application-exploitation+4
22 months ago
Previous1…969798…100Next