Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
105 results
log4j2-web-vulnerable preview

log4j2-web-vulnerable

GitHubkanitan/log4j2-web-vulnerable

A vulnerable web app for log4j2 RCE(CVE-2021-44228) exploit test.

educationexploitationlabs-practice+2
4 years ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubangelusrivera/cve-2025-49844

Scanner and educational guide for CVE-2025-49844 (RediShell), a Redis Lua scripting use-after-free vulnerability. Checks Redis servers for exposure,…

database-securityeducationexploitation+4
111 months ago
CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE preview

CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE

GitHubyunfeige18/cve-2026-1281-cve-2026-1340-ivanti-epmm-rce

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

educationexploitationpenetration-testing+2
37 months ago
WordPress-Path-Traversal-CVE-2019-11447 preview

WordPress-Path-Traversal-CVE-2019-11447

GitHubcapivara-research/wordpress-path-traversal-cve-2019-11447

Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including…

educationexploitationlabs-practice+3
11 days ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
9375 days ago
cve-2022-24785-poc-lab preview

cve-2022-24785-poc-lab

GitHubanomalousvectors/cve-2022-24785-poc-lab

Moment.js vuln lab

educationlabs-practicevulnerability-analysis+2
11 year ago
CVE-2023-6000 preview

CVE-2023-6000

GitHubrxerium/cve-2023-6000

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them,…

educationpenetration-testingvulnerability-scanners+2
211 months ago
CVE-2024-1813-POC preview

CVE-2024-1813-POC

GitHubmobetasec/cve-2024-1813-poc

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

ctfeducationlabs-practice+4
2 months ago
CVE-2026-32722 preview

CVE-2026-32722

GitHub0xmrma/cve-2026-32722

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

educationpapers-researchpenetration-testing+3
15 months ago
CVE-2024-10924-PoC preview

CVE-2024-10924-PoC

GitHubmaalfer/cve-2024-10924-poc

Bypass del MFA en WordPress con el plugin Really Simple Security instalado entre las versiones 9.0.0 – 9.1.1.1.

authentication-authorizationeducationexploitation+3
71 year ago
poc-CVE-2019-9053 preview

poc-CVE-2019-9053

GitHubrideckszz/poc-cve-2019-9053

PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em…

ctfeducationlabs-practice+3
13 months ago
cve-2021-44228 preview

cve-2021-44228

GitHubnikolas-charalambidis/cve-2021-44228

A simple simulation of the infamous CVE-2021-44228 issue.

code-analysiseducationexploitation+3
4 years ago
CVE-2025-68613-n8n-lab preview

CVE-2025-68613-n8n-lab

GitHubr4j3sh-com/cve-2025-68613-n8n-lab

Analysis of CVE-2025-68613

educationexploitationlabs-practice+2
9 months ago
log4j2-exploit preview

log4j2-exploit

GitHubspasam/log4j2-exploit

log4j2 Log4Shell CVE-2021-44228 proof of concept

educationexploitationpayload-development+3
24 years ago
spring-boot-log4j-cve-2021-44228-docker-lab preview

spring-boot-log4j-cve-2021-44228-docker-lab

GitHubtwseptian/spring-boot-log4j-cve-2021-44228-docker-lab

Spring Boot Log4j - CVE-2021-44228 Docker Lab

command-and-controleducationexploitation+4
274 years ago
vuln_spring_log4j2 preview

vuln_spring_log4j2

GitHubrecanavar/vuln_spring_log4j2

Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228

educationexploitationlabs-practice+3
4 years ago
Vulnerable-Lab-NextJS-CVE-2025-29927 preview

Vulnerable-Lab-NextJS-CVE-2025-29927

GitHubkamal-418/vulnerable-lab-nextjs-cve-2025-29927

Deliberately vulnerable Next.js application designed for practicing exploitation of CVE-2025-29927, with a tutorial video for guided learning.

ctfeducationlabs-practice+2
15 months ago
CVE-2022-28986 preview

CVE-2022-28986

GitHubflaviupopescu/cve-2022-28986

A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationeducationids-ips-evasion+3
24 years ago
Previous123456Next