Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k1 day ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k10h 54m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k10h 22m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
gha-lab-677752506e preview

gha-lab-677752506e

GitHubpvharmo2/gha-lab-677752506e

Authorized security-research lab reproducing CVE-2026-42298 (pull_request_target docker-build RCE in pr-docker-build.yml) — flattened snapshot of…

vulnerability-analysisexploitationeducation+2
2 days ago
GitLab-CVE-2023-7028 preview

GitLab-CVE-2023-7028

GitHubfeartheploto/gitlab-cve-2023-7028

Mock vulnerable GitLab instance reproducing CVE-2023-7028 password reset hijack. Demonstrates array-based email parameter exploitation and account…

vulnerability-analysisexploitationweb-application-exploitation+2
3 days ago
CVE-2024-38063 preview

CVE-2024-38063

GitHubhibanitt/cve-2024-38063

In-depth technical analysis and proof-of-concept for CVE-2024-38063, a critical Windows IPv6 kernel RCE. Includes root-cause breakdown, Scapy-based…

vulnerability-analysisexploitationpapers-research+3
3 days ago
log4shell-exploitation-lab preview

log4shell-exploitation-lab

GitHubwafeeq-fareed/log4shell-exploitation-lab

CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation

vulnerability-analysisexploitationweb-security+3
2 days ago
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubritinify/cve-2025-29927-poc

Proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes a vulnerable target lab and Python script to verify…

exploitationweb-application-exploitationctf+3
4 days ago
cve-2026-32475-elementor-pro-lab preview

cve-2026-32475-elementor-pro-lab

GitHubdinosn/cve-2026-32475-elementor-pro-lab

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

vulnerability-analysisexploitationweb-application-exploitation+4
24 days ago
EXPLOIT-CVE-2026-22778 preview

EXPLOIT-CVE-2026-22778

GitHubjoaovicdev/exploit-cve-2026-22778

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

vulnerability-analysisexploitationweb-application-exploitation+5
4 days ago
gha-lab-6c3094af9e preview

gha-lab-6c3094af9e

GitHubpvharmo2/gha-lab-6c3094af9e

Authorized security-research lab reproducing CVE-2026-27941 (pwn request in pull_request_target workflows) — snapshot of openlit/openlit

vulnerability-analysisexploitationeducation+1
4 days ago
cve-2026-75604 preview

cve-2026-75604

GitHubfortbridge-uk/cve-2026-75604

Reproduction lab and exploit tooling for CVE-2026-75604, a path traversal in Next.js incremental cache leading to unauthenticated RCE on Windows.…

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
CVE-2026-52810 preview

CVE-2026-52810

GitHubhorkimhab/cve-2026-52810

Educational repository for learning and researching CVE-2026-52810 in controlled environments, with setup instructions and links to related PoC…

vulnerability-analysisexploitationeducation+2
5 days ago
cve-2026-31431 preview

cve-2026-31431

GitHubfranklinf25/cve-2026-31431

Analyzes CVE-2026-31431, a Linux kernel AF_ALG AEAD vulnerability, providing a safe detector, in-lab LPE exploit, and QEMU-based A/B kernel lab for…

exploit-frameworksvulnerability-analysisexploitation+3
4 days ago
CVE-2026-11613 preview

CVE-2026-11613

GitHubwayang1337/cve-2026-11613

Divi Ajax Filter <= 5.1.2 Unauthenticated Local File Inclusion via 'custom_loop_template'

vulnerability-analysisexploitationweb-application-exploitation+3
4 days ago
gha-lab-b5c1313658 preview

gha-lab-b5c1313658

GitHubpvharmo2/gha-lab-b5c1313658

Authorized security-research lab reproducing CVE-2026-1699 (pwn request in preview.yml) — snapshot of eclipse-theia/theia-website

vulnerability-analysiseducationcurated-resources+1
5 days ago
CUAHarm preview

CUAHarm

GitHubdb-ol/cuaharm

Benchmark for evaluating safety risks of computer-using agents, with 104 realistic misuse scenarios across seven malicious categories, supporting…

vulnerability-analysissecurity-virtualizationpenetration-testing+3
111 months ago
cve-2026-47627 preview

cve-2026-47627

GitHubanekazek/cve-2026-47627

Proof-of-concept exploit for CVE-2026-47627, a path traversal vulnerability in NVIDIA Triton Inference Server leading to arbitrary file write via…

vulnerability-analysisexploitationweb-application-exploitation+3
6 days ago
CVE-2026-19949 preview

CVE-2026-19949

GitHubhorkimhab/cve-2026-19949

Educational repository providing proof-of-concept for CVE-2026-19949, intended for authorized security research and testing in isolated environments.

vulnerability-analysisexploitationpenetration-testing+3
6 days ago
skill-safety-bench preview

skill-safety-bench

GitHubai45lab/skill-safety-bench

Benchmark for evaluating AI agent safety against attacks embedded in skill-facing context, with 155 cases across 6 risk domains, measuring task…

educationai-securityadversarial-attack+1
303 months ago
dynast-bench preview

dynast-bench

GitHubj3ssie/dynast-bench

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

vulnerability-scannersweb-vulnerability-scannersapi-security-testing+4
7 days ago
Previous123…100Next