Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k16h 38m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k16h 6m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
log4stdin preview

log4stdin

GitHubaajuvonen/log4stdin

A Java application intentionally vulnerable to CVE-2021-44228

vulnerability-analysisexploitationweb-application-exploitation+3
3 years ago
ctf-cve-2024-4577 preview

ctf-cve-2024-4577

GitHuba1ex-var1amov/ctf-cve-2024-4577

CTF challenge demonstrating CVE-2024-4577 PHP CGI argument injection, with vulnerable app, attack scripts, and Kubernetes/Docker deployment for…

vulnerability-analysisexploitationweb-application-exploitation+3
1 year ago
ctf-cve-2019-11043 preview

ctf-cve-2019-11043

GitHuba1ex-var1amov/ctf-cve-2019-11043

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

privilege-escalationcontainer-securityvulnerability-analysis+8
1 year ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubzeyad-azima/cve-2022-1388

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

vulnerability-analysisexploitationweb-application-exploitation+3
133 years ago
Samba-CVE-2017-7494 preview

Samba-CVE-2017-7494

GitHubzer0d0y/samba-cve-2017-7494

搭建漏洞利用测试环境

vulnerability-analysisexploitationpenetration-testing+2
18 years ago
CVE-2015-1578 preview

CVE-2015-1578

GitHubzeppperoni/cve-2015-1578

Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.

payload-generationexploitationshellcode+5
3 years ago
CVE-2025-64459 preview

CVE-2025-64459

GitHubz3yr0xx/cve-2025-64459

CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment…

vulnerability-analysisweb-application-exploitationweb-security+3
9 months ago
CVE-2015-3306 preview

CVE-2015-3306

GitHubz3r0space/cve-2015-3306

This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.

vulnerability-analysisexploitationctf+3
1 year ago
Bootstrap-with-XSS preview

Bootstrap-with-XSS

GitHubyumeae/bootstrap-with-xss

A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040)

vulnerability-analysisweb-application-exploitationweb-security+3
41 year ago
CVE-2022-28346 preview

CVE-2022-28346

GitHubyougina/cve-2022-28346

SQL injection in QuerySet.annotate(), aggregate(), and extra()

vulnerability-analysisweb-application-exploitationpenetration-testing+2
24 years ago
CVE-2021-35042 preview

CVE-2021-35042

GitHubyougina/cve-2021-35042

SQL injection via unsanitized QuerySet.order_by() input

vulnerability-analysisweb-application-exploitationpenetration-testing+2
135 years ago
LOGJ4_PocShell_CVE-2021-44228 preview

LOGJ4_PocShell_CVE-2021-44228

GitHubyanghyperdata/logj4_pocshell_cve-2021-44228

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

payload-generationvulnerability-analysisexploitation+3
2 years ago
nextjs-cve-2025-29927 preview

nextjs-cve-2025-29927

GitHubyeondg/nextjs-cve-2025-29927

vulnerable-nextjs-14-CVE-2025-29927

authentication-authorizationvulnerability-analysisweb-application-exploitation+3
1 year ago
CVE-2017-5638-POC preview

CVE-2017-5638-POC

GitHubxernary/cve-2017-5638-poc

Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
jboss-deserialization preview

jboss-deserialization

GitHubxcatolin/jboss-deserialization

JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.

vulnerability-analysisexploitationweb-application-exploitation+3
5 years ago
CVE-2025-55183_POC preview

CVE-2025-55183_POC

GitHubx-cotang/cve-2025-55183_poc

CVE-2025-55183 POC

vulnerability-analysisexploitationweb-application-exploitation+2
49 months ago
CVE-2025-54918-POC preview

CVE-2025-54918-POC

GitHubwh0am123/cve-2025-54918-poc

POC for CVE-2025-54918 and a technical demonstration.

privilege-escalationvulnerability-analysisexploitation+5
648 months ago
SSI-CVE-2022-21661 preview

SSI-CVE-2022-21661

GitHubwellingtonespindula/ssi-cve-2022-21661

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

password-crackingvulnerability-analysisexploitation+3
62 years ago
Previous1…979899100Next