Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Labs & Practice | Kitploit
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k13h 42m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k13h 10m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
DFIR-LABS preview

DFIR-LABS

GitHubazr43lkn1ght/dfir-labs

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

disk-forensicsmemory-forensicsnetwork-forensics+6
5799 months ago
vulnerability-poc preview

vulnerability-poc

GitHubfankh/vulnerability-poc

CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security…

vulnerability-analysisexploitationweb-security+5
653 days ago
CVE-2026-7899 preview

CVE-2026-7899

GitHubhorkimhab/cve-2026-7899

Educational repository for researching CVE-2026-7899, providing setup instructions and resources for authorized security testing in isolated…

vulnerability-analysisexploitationeducation+2
7 days ago
CVE-2026-9586 preview

CVE-2026-9586

GitHubhorkimhab/cve-2026-9586

Educational repository for CVE-2026-9586, providing proof-of-concept resources and guidance for authorized security research, vulnerability analysis,…

vulnerability-analysisexploitationeducation+2
7 days ago
NetSec-CVE-2023-4357 preview

NetSec-CVE-2023-4357

GitHubshihongsu/netsec-cve-2023-4357

Reproduces CVE-2023-4357 in Google Chrome to demonstrate XML/XSLT-based file access bypass, with analysis and proof-of-concept for educational…

vulnerability-analysisexploitationweb-application-exploitation+2
7 days ago
CVE-2024-49138-SOC-Investigation preview

CVE-2024-49138-SOC-Investigation

GitHubadisasoc/cve-2024-49138-soc-investigation

SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege…

privilege-escalationmalware-analysisdigital-forensics+4
7 days ago
gha-lab-ee08e207a8 preview

gha-lab-ee08e207a8

GitHubpvharmo2/gha-lab-ee08e207a8

Authorized security-research lab reproducing CVE-2024-4253 (GHSA-r897-wrpm-h4vw): workflow_run command injection in gradio-app/gradio's…

vulnerability-analysisexploitationeducation+1
7 days ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

vulnerability-analysisexploitationweb-application-exploitation+5
118 days ago
log4j2-vuln-lab preview

log4j2-vuln-lab

GitHub14free/log4j2-vuln-lab

CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证

vulnerability-analysisexploitationweb-application-exploitation+3
8 days ago
gha-lab-0ba60e6456 preview

gha-lab-0ba60e6456

GitHubpvharmo2/gha-lab-0ba60e6456

Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)

vulnerability-analysisexploitationeducation+1
8 days ago
CVE-2018-14667_Lab_POC preview

CVE-2018-14667_Lab_POC

GitHubr4ch1d0/cve-2018-14667_lab_poc

Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

vulnerability-analysisexploitationweb-application-exploitation+2
8 days ago
activemq-cve-lab preview

activemq-cve-lab

GitHubradsih/activemq-cve-lab

ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示

vulnerability-scannersexploitationpenetration-testing+2
9 days ago
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

container-securityexploit-frameworksvulnerability-analysis+7
18 days ago
EXPLOIT-CVE-2026-56121 preview

EXPLOIT-CVE-2026-56121

GitHubjoaovicdev/exploit-cve-2026-56121

Proof-of-concept exploit for CVE-2026-56121, an unauthenticated RCE in Feast's registry gRPC server via unsafe dill deserialization. Includes a…

vulnerability-analysisexploitationweb-application-exploitation+3
9 days ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubalvarosr/cve-2025-5548

Documented technical analysis and controlled exploitation of CVE-2025-5548 in FreeFloat FTP Server, covering lab setup, static/dynamic binary…

vulnerability-analysisexploitationreverse-engineering+5
5 months ago
shellshock-cve-lab preview

shellshock-cve-lab

GitHubvaibhav91one/shellshock-cve-lab

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

vulnerability-analysisexploitationweb-security+2
10 days ago
drupalgeddon2-cve-lab preview

drupalgeddon2-cve-lab

GitHubvaibhav91one/drupalgeddon2-cve-lab

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

container-securityvulnerability-analysisweb-application-exploitation+3
10 days ago
log4shell-cve-lab preview

log4shell-cve-lab

GitHubvaibhav91one/log4shell-cve-lab

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

vulnerability-analysisexploitationweb-security+2
10 days ago
Previous1234…100Next