Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
10 results
zenbuster preview

zenbuster

GitHub0xtas/zenbuster

Multi-threaded URL enumeration/content-discovery tool in Python.

ctfinformation-gatheringpenetration-testing+2
1082 years ago
EverShop-Lab-CVE-2026-25993 preview

EverShop-Lab-CVE-2026-25993

GitHubmoxitpanchal/evershop-lab-cve-2026-25993

Docker-based lab for exploiting CVE-2026-25993, a second-order SQL injection in EverShop. Deploy, enumerate, and dump the database via crafted…

ctfeducationlabs-practice+2
12 months ago
0l4bs preview

0l4bs

GitHubtegal1337/0l4bs

Cross-site scripting labs for web application security enthusiasts

ctfeducationlabs-practice+1
3505 years ago
CVE-2023-24329-lab preview

CVE-2023-24329-lab

GitHubjithinodattu/cve-2023-24329-lab

Self-contained Docker lab demonstrating CVE-2023-24329, a Python urllib parser differential that bypasses URL scheme and host filters, with…

ctfeducationexploitation+4
5 months ago
iGoat-Swift preview

iGoat-Swift

GitHubowasp/igoat-swift

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

ctfeducationios-security+6
4559 months ago
CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE preview

CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50365_csrf_delete_category-phpgurukul-cve

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

ctfeducationexploitation+3
1 year ago
CVE-2024-22243 preview

CVE-2024-22243

GitHubseanpesce/cve-2024-22243

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

code-analysisctfeducation+4
131 year ago
cve-2022-44268 preview

cve-2022-44268

GitHubjkobierczynski/cve-2022-44268
ctfexploitationinformation-gathering+3
1 year ago
ChamiloLMS-CVE-2023-4220 preview

ChamiloLMS-CVE-2023-4220

GitHubspeatx/chamilolms-cve-2023-4220

CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.

ctfeducationexploitation+5
5 months ago
CVE-2016-15041-mainwp-dashboard preview

CVE-2016-15041-mainwp-dashboard

GitHubflame-11/cve-2016-15041-mainwp-dashboard

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

ctfeducationlabs-practice+3
9 months ago