Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k1 day ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k10h 20m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k9h 48m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
needrestart-sudo-escalate-cve-2024-4890 preview

needrestart-sudo-escalate-cve-2024-4890

GitHubnekr0ff/needrestart-sudo-escalate-cve-2024-4890

PoC exploit for CVE-2024-4890: Sudo privilege escalation via neecdrestart (>=3.8). Ethical lab-only. Scripts in Python and C.

privilege-escalationvulnerability-analysisexploitation+3
10 months ago
ros2_CVE-2024-28231 preview

ros2_CVE-2024-28231

GitHubgrimmmbo/ros2_cve-2024-28231

Demonstrating the usage of Fastrtps-DDS vulnerability CVE-2024-28231 within Ros2

vulnerability-analysisexploitationfuzzing+3
10 months ago
CVE-2025-32463-Sudo-Privilege-Escalation preview

CVE-2025-32463-Sudo-Privilege-Escalation

GitHubankitpandey383/cve-2025-32463-sudo-privilege-escalation

Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and…

privilege-escalationvulnerability-analysisexploitation+3
9 months ago
PIL-CVE-2017-8291 preview

PIL-CVE-2017-8291

GitHubdaniilorchikov/pil-cve-2017-8291

Educational PoC for CVE-2017-8291 (GhostButt) demonstrating remote command execution via Python PIL/Pillow EPS image processing with GhostScript…

vulnerability-analysisexploitationweb-application-exploitation+3
9 months ago
CVE-2018-11235 preview

CVE-2018-11235

GitHubanonymking/cve-2018-11235

CVE-2018-11235(PoC && Exp)

vulnerability-analysisexploitationsupply-chain-security+3
17 years ago
CVE-2021-3456 preview

CVE-2021-3456

GitHubmrk336/cve-2021-3456

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

privilege-escalationexploitationlateral-movement+8
1 year ago
CVE-2017-20192-formidable-forms preview

CVE-2017-20192-formidable-forms

GitHubflame-11/cve-2017-20192-formidable-forms

Reproducible Docker lab for CVE-2017-20192 (Formidable Forms < 2.05.03 stored XSS) with automated PoC script for unauthenticated exploitation and…

vulnerability-analysisexploitationweb-application-exploitation+3
8 months ago
CVE-2026-24061-POC preview

CVE-2026-24061-POC

GitHubalter-n0x/cve-2026-24061-poc

CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing

vulnerability-analysisexploitationpenetration-testing+2
7 months ago
Log4Shell-PoC preview

Log4Shell-PoC

GitHubjosemariamicoli/log4shell-poc

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

vulnerability-analysisexploitationids-ips-evasion+6
7 months ago
CVE-2017-12611_Exploit preview

CVE-2017-12611_Exploit

GitHubzeynepsilao/cve-2017-12611_exploit

RCE project

payload-generationvulnerability-analysisexploitation+3
11 months ago
BIND-9-Cache-Poisoning-PoC---CVE-2025-40778 preview

BIND-9-Cache-Poisoning-PoC---CVE-2025-40778

GitHubsirbuvladste/bind-9-cache-poisoning-poc---cve-2025-40778

Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records.

vulnerability-analysisexploitationnetwork-security+3
8 months ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubrahul-securify/react2shell-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 demonstrating remote code execution in Next.js via prototype pollution. Includes a pre-configured…

payload-generationexploitationweb-application-exploitation+3
9 months ago
react-cve-2025-55182 preview

react-cve-2025-55182

GitHubniokagi/react-cve-2025-55182

Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions

vulnerability-analysiscode-analysisexploitation+5
8 months ago
CVE-2025-70341 preview

CVE-2025-70341

GitHubmalvector/cve-2025-70341

CVE-2025-70341: Local Privilege Escalation via TOCTOU in App-Auto-Patch

privilege-escalationvulnerability-analysisexploitation+3
6 months ago
CrafterCMS-CVE-2025-6384 preview

CrafterCMS-CVE-2025-6384

GitHubmaestro-ant/craftercms-cve-2025-6384

PoC exploit for an authenticated RCE in CrafterCMS via Groovy sandbox bypass (CVE-2025-6384)

vulnerability-analysisexploitationweb-application-exploitation+3
11 months ago
CVE-2024-32019-ndsudo-local-privilege-escalation-NetData preview

CVE-2024-32019-ndsudo-local-privilege-escalation-NetData

GitHubjulichaan/cve-2024-32019-ndsudo-local-privilege-escalation-netdata

Python PoC for Netdata LPE (CVE-2024-32019) exploiting unsanitized PATH in ndsudo to escalate privileges to root via hijacked binaries.

privilege-escalationvulnerability-analysisexploitation+3
9 months ago
CVE-2022-31199 preview

CVE-2022-31199

GitHubdeveloperfred/cve-2022-31199

Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload…

vulnerability-analysisexploitationpenetration-testing+5
9 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubahmedshamsddin/cve-2025-55182

Python exploit for CVE-2025-55182 in React Server Components, injecting a shell into Next.js 16.0.6 applications. Includes a vulnerable app for…

payload-generationvulnerability-analysisexploitation+3
9 months ago
Previous1…99100Next