Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
VulApps preview
Archived

VulApps

GitHubmedicean/vulapps

快速搭建各种漏洞环境(Various vulnerability environment)

container-securitycurated-resourceseducation+4
3.8k
5 years ago
Awesome-CloudSec-Labs preview

Awesome-CloudSec-Labs

GitHubiknowjason/awesome-cloudsec-labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

cloud-securitycontainer-securityctf+7
2.2k10 months ago
Damn-Vulnerable-GraphQL-Application preview

Damn-Vulnerable-GraphQL-Application

GitHubdolevf/damn-vulnerable-graphql-application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

api-securityapi-security-testingctf+5
1.7k1 year ago
mutillidae preview

mutillidae

GitHubwebpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

ctfeducationlabs-practice+3
1.5k1 month ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
91810 months ago
fastjson-jsontype-rce-lab preview

fastjson-jsontype-rce-lab

GitHubdinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

dynamic-analysis-sandboxingeducationexploitation+5
20424 days ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubl4rm4nd/cve-2025-55182

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

educationlabs-practicepenetration-testing+4
868 months ago
exploit-CVE-2016-9920 preview

exploit-CVE-2016-9920

GitHubt0kx/exploit-cve-2016-9920

Roundcube 1.0.0 <= 1.2.2 Remote Code Execution exploit and vulnerable container

container-securityeducationexploitation+3
482 years ago
HazProne preview

HazProne

GitHubstafordtituss/hazprone

Cloud pentesting framework deploying vulnerable-by-demand AWS resources with quest-based scenarios to teach practical penetration testing and…

cloud-securityeducationlabs-practice+2
404 years ago
vulnerable-container-hub preview

vulnerable-container-hub

GitHubowasp/vulnerable-container-hub

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

container-securityctfcurated-resources+4
303 years ago
cve-2021-42013 preview

cve-2021-42013

GitHubwalnutsecurity/cve-2021-42013

cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50

exploitationlabs-practicepenetration-testing+3
273 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubthemehackers/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

educationexploitationlabs-practice+3
235 months ago
vaas-cve-2014-6271 preview

vaas-cve-2014-6271

GitHubhmlio/vaas-cve-2014-6271

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

container-securityeducationexploitation+3
226 years ago
vuln-app-CVE-2025-55182 preview

vuln-app-CVE-2025-55182

GitHubzack0x01/vuln-app-cve-2025-55182
code-analysiseducationexploitation+5
205 months ago
vaas-cve-2014-0160 preview

vaas-cve-2014-0160

GitHubhmlio/vaas-cve-2014-0160

Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed

container-securityeducationexploitation+3
156 years ago
poc-cve-2025-55182 preview

poc-cve-2025-55182

GitHubkoadt/poc-cve-2025-55182

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

code-analysisctfdynamic-analysis-sandboxing+7
155 months ago
SpringBreakVulnerableApp preview

SpringBreakVulnerableApp

GitHubm3ssap0/springbreakvulnerableapp

WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!

educationexploitationlabs-practice+3
147 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubzeyad-azima/cve-2022-1388

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

exploitationlabs-practicepenetration-testing+3
133 years ago
Previous1234567Next