Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
553 results
mutillidae preview

mutillidae

GitHubwebpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

ctfeducationlabs-practice+3
1.5k
9 days ago
CVE-2025-31486-Simulation preview

CVE-2025-31486-Simulation

GitHubhackmelocal/cve-2025-31486-simulation

Containerized lab environment to simulate and exploit CVE-2025-31486, a path traversal vulnerability in Vite's development server, with step-by-step…

ctfeducationlabs-practice+3
1 year ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
2 months ago
CVE-2025-55182-React2Shell-Lab preview

CVE-2025-55182-React2Shell-Lab

GitHubgoultarde/cve-2025-55182-react2shell-lab

CTF lab environment exploiting CVE-2025-55182 (RCE in React Server Components) with vulnerable Next.js blog, detection scripts, and manual exploit…

ctfeducationexploitation+3
9 months ago
web-hacking-playground preview

web-hacking-playground

GitHubtakito1812/web-hacking-playground

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

ctfeducationlabs-practice+4
1712 years ago
CVE-2025-64424-Coolify- preview

CVE-2025-64424-Coolify-

GitHubandroidteacher/cve-2025-64424-coolify-

Containerized CTF lab for learning and exploiting CVE-2025-64424, a command injection RCE in Coolify. Includes vulnerable environment, walkthrough,…

container-securityctfeducation+5
17 months ago
Juiceshopgl preview

Juiceshopgl

GitLabmbrandner-group/juiceshopgl

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

ctfeducationlabs-practice+5
2 years ago
SecurityShepherd preview

SecurityShepherd

GitHubowasp/securityshepherd

Web and mobile application security training platform

ctfeducationlabs-practice+3
1.5k1 month ago
wvctf preview

wvctf

GitHubsyn-4ck/wvctf

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

ctfeducationlabs-practice+3
12 years ago
juice-shop preview

juice-shop

GitHubjuice-shop/juice-shop

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

ctfeducationlabs-practice+3
14.0k1 month ago
PortSwigger-Web-Security-Academy preview

PortSwigger-Web-Security-Academy

GitHubnu11secur1ty/portswigger-web-security-academy

Curated solutions and walkthroughs for PortSwigger Web Security Academy labs, covering web vulnerabilities, JWT attacks, and exploitation techniques…

ctfeducationpenetration-testing+2
51 month ago
CVE-2025-55182_Vulnerable-Application preview

CVE-2025-55182_Vulnerable-Application

GitHubdeepankarkumar1/cve-2025-55182_vulnerable-application

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

ctfeducationlabs-practice+3
8 months ago
Compose Aperisite preview

Compose Aperisite

GitLabaperikube/compose-aperisite

Docker Compose wrapper to deploy AperiSite, a curated platform hosting CTF writeups, security challenges, and educational resources covering web,…

ctfcurated-resourceseducation+1
15 years ago
JavaSecLab preview

JavaSecLab

GitHubwhgojp/javaseclab

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

code-analysisctfdevsecops+6
8813 months ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
486h 46m ago
BreakEscape preview

BreakEscape

GitHubcliffe/breakescape

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

ctfeducationlabs-practice+3
611h 30m ago
CVE-2025-14765-and-CVE-2025-14766 preview

CVE-2025-14765-and-CVE-2025-14766

GitHubinfosecantara/cve-2025-14765-and-cve-2025-14766

Interactive browser-based lab simulating Chrome memory corruption vulnerabilities (CVE-2025-14765/14766) for safe security training, featuring…

binary-exploitationctfeducation+4
29 months ago
CVE-2024-32002 preview

CVE-2024-32002

GitHubflojboj/cve-2024-32002

Educational exploit script for CVE-2024-32002 (Git RCE) with automated setup, designed for CTF environments and security training.

ctfeducationexploitation+2
2 years ago
Previous12…31Next