Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k1 month ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k6h 53m ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k1 day ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k7 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k1 day ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2398 results
Holistic-Deconstruction-of-CVE-2019-5736- preview

Holistic-Deconstruction-of-CVE-2019-5736-

GitHubsastraadiwiguna-purpleeliteteaming/holistic-deconstruction-of-cve-2019-5736-

This repository provides a high-fidelity technical deconstruction and production-ready exploitation suite for CVE-2019-5736. It demonstrates how a…

privilege-escalationvulnerability-analysisexploitation+6
7 months ago
DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint- preview

DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-

GitHubsastraadiwiguna-purpleeliteteaming/ddos-purple-teaming-offensive-multi-vector-7-tier-defensive-holistic-blueprint-

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

defensive-toolsvulnerability-analysisexploitation+9
7 months ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

vulnerability-analysisexploitationweb-application-exploitation+5
11 year ago
mongobleed preview

mongobleed

GitHubadolfbharath/mongobleed

CVE-2025-14847 explaination and lab

vulnerability-analysisnetwork-securitycryptography+3
18 months ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubjoe1sn/cve-2022-22965

CVE-2022-22965 Environment

vulnerability-analysisexploitationweb-application-exploitation+2
14 years ago
RuoYI-4.2-Shiro-721-Docker-PoC preview

RuoYI-4.2-Shiro-721-Docker-PoC

GitHubbaihliu/ruoyi-4.2-shiro-721-docker-poc

若依4.2 (Shiro 1.4.1) Shiro-721 (CVE-2019-12422)漏洞复现环境

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
CVE-2022-0185-POC preview

CVE-2022-0185-POC

GitHubprabeershakya/cve-2022-0185-poc

Proof-of-concept exploit for CVE-2022-0185, a Linux kernel heap buffer overflow enabling local privilege escalation and container escape via FUSE and…

privilege-escalationvulnerability-analysisexploitation+4
6 months ago
CVE-2024-11635 preview

CVE-2024-11635

GitHubvigilante-1337/cve-2024-11635

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the…

vulnerability-analysisexploitationweb-application-exploitation+3
7 months ago
CVE-2023-29386 preview

CVE-2023-29386

GitHubvigilante-1337/cve-2023-29386

PoC CVE-2023-29386 — Manager for Icomoon < 2.1 - Unauthenticated Arbitrary File Upload

vulnerability-analysisexploitationweb-application-exploitation+3
11 months ago
CVE-2019-9978-RCE-PoC preview

CVE-2019-9978-RCE-PoC

GitHubvaidehim55/cve-2019-9978-rce-poc

A custom Python proof-of-concept showcasing root-cause analysis and exploitation of CVE 2019-9978 (Social Warfare plugin),focusing on practical RFI…

vulnerability-analysisexploitationweb-application-exploitation+3
8 months ago
cve-2025-55182 preview

cve-2025-55182

GitHubliamromanis101/cve-2025-55182

Python exploit for CVE-2025-55182, a server-side JavaScript injection in Next.js/React enabling remote code execution via malformed multipart form…

vulnerability-analysisexploitationweb-application-exploitation+3
9 months ago
offensive-security-adversary-emulation preview

offensive-security-adversary-emulation

GitHubkhalilu020/offensive-security-adversary-emulation

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

reconnaissancevulnerability-analysisexploitation+5
1 month ago
TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation preview

TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation

GitHubthreatradarai/trai-001-critical-rce-vulnerability-in-apache-parquet-cve-2025-30065-simulation

A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked…

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
LlamaStack-RCE-Deterministic-Supply-Chain-Exploitation-Hardening-Framework-CVE-2024-50050- preview

LlamaStack-RCE-Deterministic-Supply-Chain-Exploitation-Hardening-Framework-CVE-2024-50050-

GitHubsastraadiwiguna-purpleeliteteaming/llamastack-rce-deterministic-supply-chain-exploitation-hardening-framework-cve-2024-50050-

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

exploit-frameworksvulnerability-analysisdata-exfiltration+9
7 months ago
CVE-2024-3408-dtale preview

CVE-2024-3408-dtale

GitHubflame-11/cve-2024-3408-dtale

Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE

vulnerability-analysisexploitationweb-application-exploitation+3
8 months ago
CVE-2025-48384 preview

CVE-2025-48384

GitHubs41r4j/cve-2025-48384

GIT vulnerability | Carriage Return and RCE on cloning

vulnerability-analysisexploitationsupply-chain-security+3
11 months ago
TraditionalJay preview

TraditionalJay

GitHubastraljays/traditionaljay

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

vulnerability-analysisexploitationweb-application-exploitation+5
1 month ago
CVE-2023-20198 preview

CVE-2023-20198

GitHubreligan/cve-2023-20198

A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software…

privilege-escalationvulnerability-analysisexploitation+6
8 months ago
Previous1…969798…100Next