Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k13h 42m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k13h 10m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
TraditionalJay preview

TraditionalJay

GitHubastraljays/traditionaljay

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

vulnerability-analysisexploitationweb-application-exploitation+5
1 month ago
CVE-2023-20198 preview

CVE-2023-20198

GitHubreligan/cve-2023-20198

A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software…

privilege-escalationvulnerability-analysisexploitation+6
8 months ago
CVE-2025-55182-LAB preview

CVE-2025-55182-LAB

GitHubbigbluewhale111/cve-2025-55182-lab

Hands-on lab environment for reproducing CVE-2025-55182, providing setup instructions and notes for security researchers to analyze and understand…

vulnerability-analysisexploitationpenetration-testing+2
8 months ago
soc-investigation-powershell-edrfreeze preview

soc-investigation-powershell-edrfreeze

GitHubzedocun/soc-investigation-powershell-edrfreeze

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

defensive-toolsioc-managementprivilege-escalation+7
16 months ago
log4j-pcap-activity preview

log4j-pcap-activity

GitHubapipia/log4j-pcap-activity

A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)

packet-sniffing-analysisvulnerability-analysisexploitation+3
14 years ago
CVE-2024-32019-PoC preview

CVE-2024-32019-PoC

GitHub80ottanta80/cve-2024-32019-poc

Bash script for Privilege Escalation via "ndsudo" (Netdata Local Exploit)

privilege-escalationvulnerability-analysisexploitation+3
10 months ago
CVE-2025-23167 preview

CVE-2025-23167

GitHubabhisek3122/cve-2025-23167

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400 preview

SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400

GitHubhashdr1ft/soc274-palo-alto-networks-pan-os-command-injection-vulnerability-exploitation-cve-2024-3400

SOC lab exercise for analyzing and responding to Palo Alto Networks PAN-OS command injection vulnerability (CVE-2024-3400) with step-by-step incident…

vulnerability-analysisweb-application-exploitationcommand-and-control+3
11 year ago
CVE-2017-16995 preview

CVE-2017-16995

GitHubxxxtectationxxx/cve-2017-16995

Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04

privilege-escalationvulnerability-analysisexploitation+3
1 year ago
Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets- preview

Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-

GitHubartemcyberlab/project-project-chimera-exploiting-a-modern-wordpress-xxe-to-pillage-secrets-

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

privilege-escalationreconnaissancepassword-attacks+8
11 year ago
Struts2Vuln preview

Struts2Vuln

GitHubmike-williams/struts2vuln

Struts 2 web app that is vulnerable to CVE-2017-98505 and CVE-2017-5638

vulnerability-analysisexploitationweb-application-exploitation+3
18 years ago
cve-2017-5123 preview

cve-2017-5123

GitHubnabilboudra/cve-2017-5123

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

privilege-escalationexploitationweb-application-exploitation+5
8 months ago
CVE-2022-36804-Bitbucket-RCE-Analysis preview

CVE-2022-36804-Bitbucket-RCE-Analysis

GitHubdanielhallbro/cve-2022-36804-bitbucket-rce-analysis

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

vulnerability-analysisexploitationweb-application-exploitation+6
6 months ago
Email-exploit-Moniker-Link-CVE-2024-21413- preview

Email-exploit-Moniker-Link-CVE-2024-21413-

GitHubyass2400012/email-exploit-moniker-link-cve-2024-21413-

Proof-of-concept exploit for CVE-2024-21413 using Moniker Link in HTML email to trigger SMB connection and capture netNTLMv2 hashes via Responder.…

password-crackingexploitationphishing+6
11 months ago
cve-2025-55182-poc preview

cve-2025-55182-poc

GitHubmooowu/cve-2025-55182-poc

Lab environment and PoC exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components. Includes vulnerable app,…

vulnerability-analysisexploitationweb-application-exploitation+6
7 months ago
cve-2025-55182-test-lab-windows preview

cve-2025-55182-test-lab-windows

GitHubfankh/cve-2025-55182-test-lab-windows

Docker-based test lab for CVE-2025-55182 (React2Shell) RCE vulnerability in React 19.1.0/Next.js 15.1.0. Includes exploit scripts, WAF bypass testing…

vulnerability-analysisexploitationweb-application-exploitation+6
9 months ago
CVE-2025-55184 preview

CVE-2025-55184

GitHubtarekhshaikh13/cve-2025-55184

Target Code + Exploit

vulnerability-analysisexploitationweb-application-exploitation+3
8 months ago
CVE-2025-1974 preview

CVE-2025-1974

GitHubboianeduard/cve-2025-1974

ingress-nginx admission controller RCE escalation PoC

privilege-escalationcontainer-securityvulnerability-analysis+8
7 months ago
Previous1…979899100Next