Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k1 month ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k10h 21m ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k3 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k1 day ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k7 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k1 day ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2409 results
CVE-2026-27541-Analysis-Lab preview

CVE-2026-27541-Analysis-Lab

GitHubrootdirective-sec/cve-2026-27541-analysis-lab

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

vulnerability-analysisexploitationweb-application-exploitation+4
5 months ago
CVE-2026-1581-Analysis-Lab preview

CVE-2026-1581-Analysis-Lab

GitHubrootdirective-sec/cve-2026-1581-analysis-lab

Reproduces CVE-2026-1581, an unauthenticated time-based SQL injection in wpForo Forum <=2.4.14, with a Docker lab and PoC to demonstrate the…

vulnerability-analysisexploitationweb-application-exploitation+3
16 months ago
CVE-2026-65643 preview

CVE-2026-65643

GitHubhorkimhab/cve-2026-65643

Educational repository for learning and researching CVE-2026-65643 in controlled environments, with setup scripts and references for authorized…

vulnerability-analysispenetration-testingeducation+2
13 days ago
Spring-Cloud-Function-SpEL preview

Spring-Cloud-Function-SpEL

GitHubpizz33/spring-cloud-function-spel

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

vulnerability-analysisexploitationweb-application-exploitation+2
244 years ago
llm-agent-testbed preview

llm-agent-testbed

GitHubpie-script/llm-agent-testbed

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

vulnerability-analysispenetration-testingeducation+4
137 days ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

web-application-exploitationweb-securitypenetration-testing+3
717 days ago
FuzzingBrain-Bench preview

FuzzingBrain-Bench

GitHubfuzzingbrain/fuzzingbrain-bench

A benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java).

dynamic-analysis-sandboxingvulnerability-analysisfuzzing+3
59 days ago
CVE-2015-5287 preview

CVE-2015-5287

GitHubhorkimhab/cve-2015-5287

Local privilege escalation exploit for CVE-2015-5287 targeting RHEL 7.0/7.1 via abrt/sosreport, intended for authorized security testing and…

privilege-escalationvulnerability-analysisexploitation+2
14 days ago
hacktivity-vulns-exploits-lab preview

hacktivity-vulns-exploits-lab

GitHubocfagb/hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit,…

vulnerability-analysisexploitationpost-exploitation+5
14 days ago
specterops-k8s-red-teamers-libvirt-patch preview

specterops-k8s-red-teamers-libvirt-patch

GitHubgregdurys/specterops-k8s-red-teamers-libvirt-patch

Unofficial libvirt patch for the free SpecterOps Kubernetes for Red Teamers lab

cloud-securityeducationred-teaming+1
1311 days ago
CVE-2026-3395-Lab preview

CVE-2026-3395-Lab

GitHubrootdirective-sec/cve-2026-3395-lab

Educational Docker lab demonstrating CVE-2026-3395, an unauthenticated RCE in MaxSite CMS via the run_php plugin, with vulnerable and patched…

vulnerability-analysisexploitationweb-application-exploitation+2
16 months ago
cve-2023-23397-purple-team preview

cve-2023-23397-purple-team

GitHubpraneethnaidu1910-cmd/cve-2023-23397-purple-team

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

exploitationphishingeducation+3
14 days ago
cve-2026-31431 preview

cve-2026-31431

GitHubvasyapokemon/cve-2026-31431

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

privilege-escalationvulnerability-analysisexploitation+8
4 months ago
CVE-2026-2005_lab preview

CVE-2026-2005_lab

GitHubstvm8/cve-2026-2005_lab

Self-contained Docker lab for practicing exploitation of CVE-2026-2005, a heap buffer overflow in PostgreSQL's pgcrypto extension, enabling privilege…

vulnerability-analysisexploitationctf+4
4 months ago
CVE-2026-39987-Lab preview

CVE-2026-39987-Lab

GitHubrootdirective-sec/cve-2026-39987-lab

Local Docker lab reproducing CVE-2026-39987, a pre-auth RCE in marimo's terminal WebSocket. Compares vulnerable and patched versions with least-harm…

container-securityvulnerability-analysisexploitation+3
14 months ago
CVE-2026-34197-Lab preview

CVE-2026-34197-Lab

GitHubrootdirective-sec/cve-2026-34197-lab

Docker lab demonstrating CVE-2026-34197, an Apache ActiveMQ Classic RCE via Jolokia. Includes a safe detector and a local-only PoC with fixed…

vulnerability-analysisexploitationweb-application-exploitation+3
4 months ago
cve-2024-4577-lab preview

cve-2024-4577-lab

GitHubkhwajasaad267-coder/cve-2024-4577-lab

Docker-based CTF lab demonstrating CVE-2024-4577 PHP-CGI argument injection leading to RCE. Includes vulnerable PHP 5.4.1 CGI, exploit scripts, and…

vulnerability-analysisexploitationweb-application-exploitation+4
15 days ago
HTB-Snapped-Writeup preview

HTB-Snapped-Writeup

GitHubkarimelsheikh1/htb-snapped-writeup

HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race…

privilege-escalationvulnerability-analysisexploitation+5
14 months ago
Previous1…456…100Next