Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k1 month ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k10h 21m ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k3 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k1 day ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k7 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k1 day ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2409 results
CVE-2025-32463-Sudo-Privilege-Escalation preview

CVE-2025-32463-Sudo-Privilege-Escalation

GitHubankitpandey383/cve-2025-32463-sudo-privilege-escalation

Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and…

privilege-escalationvulnerability-analysisexploitation+3
9 months ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

vulnerability-analysisexploitationweb-application-exploitation+5
11 year ago
CVE-2022-4096 preview

CVE-2022-4096

GitHubaminetitrofine/cve-2022-4096

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

iot-securityexploitationweb-security+3
3 years ago
day10-nextjs-middleware-lab preview

day10-nextjs-middleware-lab

GitHubamalpvatayam67/day10-nextjs-middleware-lab

Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)

authentication-authorizationvulnerability-analysisweb-application-exploitation+3
11 months ago
day09-bentoml-deser-lab preview

day09-bentoml-deser-lab

GitHubamalpvatayam67/day09-bentoml-deser-lab

ay 09 — CVE-2025-27520 (BentoML-style insecure deserialization) — Local Docker lab

vulnerability-analysisexploitationweb-security+3
11 months ago
day08-CISCO-fmc-sim preview

day08-CISCO-fmc-sim

GitHubamalpvatayam67/day08-cisco-fmc-sim

This is a minimal, educational simulation that demonstrates the _impact_ class of a management-plane parsing RCE (inspired by CVE-2025-20265). It…

vulnerability-analysisexploitationweb-application-exploitation+3
111 months ago
day06-foxcms-rce preview

day06-foxcms-rce

GitHubamalpvatayam67/day06-foxcms-rce

This tiny lab simulates the core idea behind CVE-2025-29306: unsafe use of `unserialize()` on attacker-controlled input leading to remote code…

vulnerability-analysisexploitationweb-application-exploitation+2
11 months ago
day05-grafana-sqlexpr-lab preview

day05-grafana-sqlexpr-lab

GitHubamalpvatayam67/day05-grafana-sqlexpr-lab

Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)

vulnerability-analysisexploitationweb-security+3
0 years ago
day04-nexus-4956 preview

day04-nexus-4956

GitHubamalpvatayam67/day04-nexus-4956

Nexus Repository 3 Path Traversal (CVE-2024-4956)

container-securityvulnerability-analysisexploitation+3
1 year ago
day01-sessionreaper-lab preview

day01-sessionreaper-lab

GitHubamalpvatayam67/day01-sessionreaper-lab

This is a tiny lab that simulates the core idea reported for CVE-2025-54236 (“SessionReaper”)

vulnerability-analysisweb-securityctf+2
1 year ago
react2shell-lab preview

react2shell-lab

GitHubalsaut1/react2shell-lab

CVE-2025-55182 React2Shell PoC lab

vulnerability-analysiscode-analysisexploitation+7
79 months ago
log4j-cve-2021-44228-sample preview

log4j-cve-2021-44228-sample

GitHubalpacamybags118/log4j-cve-2021-44228-sample

Sample docker-compose setup to show how this exploit works

vulnerability-analysisexploitationweb-application-exploitation+3
24 years ago
react-cve-2025-55182-lab preview

react-cve-2025-55182-lab

GitHubalexandre-briongos-wavestone/react-cve-2025-55182-lab

Dockerized lab demonstrating CVE-2025-55182, a React Server Components vulnerability, with a proof-of-concept exploit for security research and…

vulnerability-analysisexploitationweb-application-exploitation+3
9 months ago
CVE-2024-47167-Environment-Setup preview

CVE-2024-47167-Environment-Setup

GitHubalexan011/cve-2024-47167-environment-setup

Sets up a Dockerized environment to reproduce and analyze CVE-2024-47167, a vulnerability in Gradio 4.40.0, with an internal HTTP server and…

vulnerability-analysisexploitationweb-application-exploitation+2
10 months ago
MassCyberCenter-Mentorship-Project- preview

MassCyberCenter-Mentorship-Project-

GitHubalej6/masscybercenter-mentorship-project-

Exploiting CVE-2023-2825 on a VM

vulnerability-analysisexploitationweb-application-exploitation+3
1 year ago
PoC-CVE-2019-10743 preview

PoC-CVE-2019-10743

GitHubalbisorua/poc-cve-2019-10743

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubalastair66/cve-2025-29927

Next.js Middleware Bypass Vulnerability

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
CVE-2019-18935 preview

CVE-2019-18935

GitHubalanbarret/cve-2019-18935

Nuclei template and validation scripts for detecting CVE-2019-18935, a critical .NET deserialization RCE in Telerik UI for ASP.NET AJAX, with…

vulnerability-scannersdynamic-analysis-sandboxingexploitation+4
19 months ago
Previous1…969798…100Next