Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
CVE-2021-23394 preview

CVE-2021-23394

GitHub0xnemian/cve-2021-23394

Docker container to setup a vulnerable elfinder version on both nginx and apache servers. Can be used to test vulnerability POC

container-securityeducationlabs-practice+3
9 months ago
log4jtest preview

log4jtest

GitHubz3bul0n/log4jtest

Terraform and Docker resources for quickly spinning up a test of CVE-2021-44428

cloud-infrastructure-securitycontainer-securityeducation+3
4 years ago
CVE-2023-38545-sample preview

CVE-2023-38545-sample

GitHubvanigori/cve-2023-38545-sample

Dockerfile containing all the necessary setup files to demo the exploit

container-securityeducationexploitation+3
32 years ago
CVE-2024-1071-Docker preview

CVE-2024-1071-Docker

GitHubmatrexdz/cve-2024-1071-docker

Docker-based lab for practicing WordPress CVE-2024-1071 exploitation with automated PoC scripts and step-by-step setup instructions.

container-securityeducationexploitation+3
12 years ago
CVE-2024-21626-old-docker-versions preview

CVE-2024-21626-old-docker-versions

GitHubsk3pper/cve-2024-21626-old-docker-versions

Analyzes and exploits a container escape vulnerability in legacy Docker/runc versions, demonstrating fd leakage to access the host filesystem, with…

container-escapecontainer-securityeducation+3
1 year ago
cve-2017-4971 preview

cve-2017-4971

GitHubcved-sources/cve-2017-4971

Docker-based vulnerable environment for CVE-2017-4971 (Spring WebFlow RCE) to practice exploitation and security testing in a controlled lab setup.

container-securityeducationexploitation+3
5 years ago
cve-2014-6271 preview

cve-2014-6271

GitHubcved-sources/cve-2014-6271

Docker container providing a vulnerable environment for CVE-2014-6271 (Shellshock) to practice exploitation and vulnerability analysis in a…

container-securityeducationexploitation+2
5 years ago
medusa preview

medusa

GitHubpantheon-security/medusa

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

ai-securitycloud-securitycode-analysis+8
97326 days ago
Exploite-CVE-2023-30212-vulnerability preview

Exploite-CVE-2023-30212-vulnerability

GitHublibasv/exploite-cve-2023-30212-vulnerability

Docker-based lab environment to exploit CVE-2023-30212, a cross-site scripting (XSS) vulnerability in OURPHP <= 7.2.0, with step-by-step setup and…

container-securityeducationexploitation+3
3 years ago
MassScanning-CVE-2025-55182 preview

MassScanning-CVE-2025-55182

GitHubmrmahile/massscanning-cve-2025-55182

A lightweight orchestrator and worker scanner setup for running large/continuous scans across split input files. This repository contains…

container-securitydevsecopsexploitation+2
6 months ago
nono preview

nono

GitHubnolabs-ai/nono

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

ai-securitycloud-securitycode-analysis+8
4.0k1 day ago
CVE-2021-3156-Baron-Samedit preview

CVE-2021-3156-Baron-Samedit

GitHubtheleopard65/cve-2021-3156-baron-samedit

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

binary-exploitationcontainer-securityeducation+5
15 months ago
CrushFTP10-Docker-CVE-2024-4040 preview

CrushFTP10-Docker-CVE-2024-4040

GitHubjuanorts/crushftp10-docker-cve-2024-4040

A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).

container-securityeducationexploitation+3
10 months ago
open-sammy preview

open-sammy

GitHubowasp/open-sammy

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

cloud-securityconfiguration-auditingcontainer-security+3
281 month ago