Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k14h 25m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k13h 54m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
CVE-2026-44789-n8n-PrototypePollution-RCE preview

CVE-2026-44789-n8n-PrototypePollution-RCE

GitHubbiitts/cve-2026-44789-n8n-prototypepollution-rce

CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified…

vulnerability-analysiscode-analysisexploitation+5
2 months ago
Dirty-Frag-CVE-2026-43284 preview

Dirty-Frag-CVE-2026-43284

GitHubatlasvector/dirty-frag-cve-2026-43284

Lab detection exercise for DirtyFrag (CVE-2026-43284) - Linux kernel privilege escalation via xfrm-ESP page cache corruption. Full write-up covering…

privilege-escalationvulnerability-analysisforensics+4
3 months ago
POC-CVE-2016-10033 preview

POC-CVE-2016-10033

GitHubastrowmist/poc-cve-2016-10033

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

vulnerability-analysisexploitationweb-application-exploitation+4
2 years ago
TraditionalJay preview

TraditionalJay

GitHubastraljays/traditionaljay

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

vulnerability-analysisexploitationweb-application-exploitation+5
1 month ago
CVE-2025-70149-SQL-Injection preview

CVE-2025-70149-SQL-Injection

GitHubanusha-khan29/cve-2025-70149-sql-injection

Security research project — SQL Injection vulnerability exploitation and mitigation

vulnerability-analysisweb-application-exploitationpenetration-testing+3
1 month ago
CVE-2021-4773 preview

CVE-2021-4773

GitHubalexs18/cve-2021-4773

Step-by-step tutorial demonstrating how to set up a vulnerable Apache 2.4.49 environment and exploit CVE-2021-41773 path traversal using Kali Linux…

vulnerability-analysisexploitationweb-application-exploitation+3
10 months ago
pocketbase-CVE-2026-44166 preview

pocketbase-CVE-2026-44166

GitHubalardiians/pocketbase-cve-2026-44166

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

vulnerability-analysisexploitationweb-application-exploitation+5
3 months ago
Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577- preview

Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-

GitHubahmedmansour93/event-id-268-rule-name-soc292-possible-php-injection-detected-cve-2024-4577-

🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This…

vulnerability-analysisweb-application-exploitationctf+3
1 year ago
Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467- preview

Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-

GitHubahmedmansour93/event-id-217-rule-name-soc254-apache-ofbiz-auth-bypass-and-code-injection-0day-cve-2023-51467-

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

vulnerability-analysisexploitationweb-security+3
1 year ago
Penetration-Testing-Assessment-23-04-2026 preview

Penetration-Testing-Assessment-23-04-2026

GitHubadmin2099/penetration-testing-assessment-23-04-2026

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

privilege-escalationreconnaissancevulnerability-scanners+9
2 months ago
CVE-2022-30190-Analysis-With-LetsDefends-Lab preview

CVE-2022-30190-Analysis-With-LetsDefends-Lab

GitHubabdibimantara/cve-2022-30190-analysis-with-letsdefends-lab

this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.

vulnerability-analysisexploitationmalware-analysis+3
4 years ago
CVE-2024-49368 preview

CVE-2024-49368

GitHubaashay221999/cve-2024-49368

Explorations of CVE-2024-49368 + Exploit Development

vulnerability-analysisexploitationweb-application-exploitation+3
1 year ago
CVE-2025-7775-vulnerable-lab preview

CVE-2025-7775-vulnerable-lab

GitHubaaqilyousuf/cve-2025-7775-vulnerable-lab

Vulnerable Dockerized web app exposing RCE, path traversal, hardcoded credentials, and insecure file uploads; an isolated lab for testing security…

vulnerability-scannersweb-application-exploitationctf+3
1 year ago
CVE-2022-23614 preview

CVE-2022-23614

GitHub4rtamis/cve-2022-23614

Proof of concept for CVE-2022-23614 (command injection in Twig)

vulnerability-analysiscode-analysisexploitation+3
3 years ago
TheMisfits-CVE-2024-8465-SQLi preview

TheMisfits-CVE-2024-8465-SQLi

GitHub19melek19/themisfits-cve-2024-8465-sqli

Intentionally vulnerable PHP web app demonstrating SQL injection authentication bypass and unauthorized data disclosure modeled after CVE-2024-8465…

vulnerability-analysisweb-application-exploitationctf+3
7 months ago
CVE-2025-13486.-CVE-2025-13486 preview

CVE-2025-13486.-CVE-2025-13486

GitHub0xnemian/cve-2025-13486.-cve-2025-13486

Vulnerable setup for CVE-2025-13486 - Advanced Custom Fields: Extended - Remote Code Execution

vulnerability-analysisexploitationweb-application-exploitation+2
9 months ago
gp_netSecDSS preview

gp_netSecDSS

GitLabahmad.zaid/netsecdss

Decision Support System for Risk Assessing Network and System Security in Small and Medium Enterprises (SMEs), A graduation project.

network-securityeducationlabs-practice
2 months ago
cve-2026-75650-magento-validation-lab preview

cve-2026-75650-magento-validation-lab

GitHubdinosn/cve-2026-75650-magento-validation-lab

Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.

vulnerability-analysisexploitationweb-security+3
21 day ago
Previous1…979899100Next