Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k1 day ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k10h 56m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k10h 24m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
CVE-2018-7422 preview

CVE-2018-7422

GitHubndr-repo/cve-2018-7422

Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
CVE-2025-32462-Exploit preview

CVE-2025-32462-Exploit

GitHubcybersentinelx1/cve-2025-32462-exploit

PoC exploit for CVE-2025-32462, a sudo privilege escalation via hostname spoofing. Demonstrates bypassing hostname-based restrictions to gain root…

privilege-escalationvulnerability-analysisexploitation+3
11 year ago
CVE-2023-22809-automated-python-exploits preview

CVE-2023-22809-automated-python-exploits

GitHubspydomain/cve-2023-22809-automated-python-exploits

Automates vulnerability check for sudo versions and privilege escalation via sudoedit if exploitable, helping users test and gain root access.

privilege-escalationvulnerability-analysisexploitation+3
11 year ago
SOC_287 preview

SOC_287

GitHubhashdr1ft/soc_287

SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]

vulnerability-analysisexploitationweb-application-exploitation+3
11 year ago
cve-2025-55182-poc preview

cve-2025-55182-poc

GitHubtrax69/cve-2025-55182-poc

Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure…

vulnerability-analysisexploitationweb-application-exploitation+6
9 months ago
Domain-Controller-DC-Exploitation-with-Metasploit-Impacket preview

Domain-Controller-DC-Exploitation-with-Metasploit-Impacket

GitHubnyambiblaise/domain-controller-dc-exploitation-with-metasploit-impacket

End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes,…

reconnaissanceexploit-frameworkspayload-generation+6
10 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcarlosaruy/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

vulnerability-scannersexploitationweb-application-exploitation+6
9 months ago
vulnerable-bsr-lab-CVE-2023-6933 preview

vulnerable-bsr-lab-CVE-2023-6933

GitHubtrex96/vulnerable-bsr-lab-cve-2023-6933

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

exploit-frameworksvulnerability-analysisweb-application-exploitation+3
11 months ago
cve-2017-9822 preview

cve-2017-9822

GitHubtnot123/cve-2017-9822

In-depth technical analysis and proof-of-concept for CVE-2017-9822, an insecure deserialization vulnerability in DotNetNuke leading to remote code…

vulnerability-analysiscode-analysisexploitation+8
11 months ago
rails-cve-2017-17917 preview

rails-cve-2017-17917

GitHubmatiasarenhard/rails-cve-2017-17917

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

vulnerability-analysiscode-analysisweb-application-exploitation+3
12 years ago
CVE-2024-4577-LetsDefend-walkthrough preview

CVE-2024-4577-LetsDefend-walkthrough

GitHubphinehasnarh/cve-2024-4577-letsdefend-walkthrough

This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)

vulnerability-analysisexploitationweb-security+3
12 years ago
CVE-2018-15133-laravel-framework preview

CVE-2018-15133-laravel-framework

GitHubflame-11/cve-2018-15133-laravel-framework

Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE) with a known APP_KEY and a /poc route for testing exploit…

container-securityvulnerability-analysisexploitation+3
8 months ago
cve-2025-66478 preview

cve-2025-66478

GitHubabhirajranjan/cve-2025-66478

Intentionally vulnerable Next.js environment for testing security scanners against CVE-2025-55182, with PoC exploit and detection guidance.

vulnerability-analysisexploitationweb-application-exploitation+3
9 months ago
CVE-2023-27372 preview

CVE-2023-27372

GitHubkiroloskhairy/cve-2023-27372

Safe PoC scanner and Docker lab for CVE-2023-27372, an RCE in SPIP CMS before 4.2.1. Verifies vulnerability via password recovery endpoint without…

vulnerability-analysisexploitationweb-application-exploitation+3
7 months ago
CVE-2025-55182-React2Shell-Lab preview

CVE-2025-55182-React2Shell-Lab

GitHubgoultarde/cve-2025-55182-react2shell-lab

CTF lab environment exploiting CVE-2025-55182 (RCE in React Server Components) with vulnerable Next.js blog, detection scripts, and manual exploit…

vulnerability-analysisexploitationweb-application-exploitation+3
8 months ago
CVE-2025-55182-PoC preview

CVE-2025-55182-PoC

GitHubevillm/cve-2025-55182-poc

Safe proof-of-concept scanner for CVE-2025-55182 with a Docker-based vulnerable Next.js stand for testing remote code execution.

vulnerability-analysisexploitationweb-application-exploitation+3
7 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubtinashelorenzi/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182, a critical unauthenticated RCE in React Server Components. Includes automated Python exploit, technical…

vulnerability-analysisexploitationweb-application-exploitation+6
8 months ago
cve-2025-55182 preview

cve-2025-55182

GitHubps-interactive/cve-2025-55182

Vulnerable REACT app in docker container and poc code - for demos

container-securityvulnerability-analysisexploitation+4
9 months ago
Previous1…9899100Next