Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
CVE-2026-75816 preview

CVE-2026-75816

GitHubabraxas/cve-2026-75816

Proof-of-concept and lab reproduction for CVE-2026-75816, an unauthenticated WordPress Frontend Admin account takeover via admin-ajax form submission.

authenticationexploitationlabs-practice+4
10 days ago
cve-2026-71362-magento-lab preview

cve-2026-71362-magento-lab

GitHubdinosn/cve-2026-71362-magento-lab

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

authentication-authorizationeducationexploitation+4
51 month ago
security-writeups preview

security-writeups

GitHubalzeaty1/security-writeups

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

ctfeducationlabs-practice+5
3 days ago
cybersecurity-projects preview

cybersecurity-projects

GitHubosxninja/cybersecurity-projects

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

ai-securitycurated-resourcesdigital-forensics+7
2811 days ago
CVE-2025-7384 preview

CVE-2025-7384

GitHubdungsocool/cve-2025-7384

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

educationexploitationlabs-practice+2
1 month ago
CVE-2024-1813-POC preview

CVE-2024-1813-POC

GitHubmobetasec/cve-2024-1813-poc

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

ctfeducationlabs-practice+4
2 months ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubrandengshifu/cve-2022-22963

CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit

educationexploitationlabs-practice+2
154 years ago
screenpipe preview

screenpipe

GitHubscreenpipe/screenpipe

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

ctfcurated-resourceseducation+8
21.8k3 hours ago
OWASPBugBounty preview

OWASPBugBounty

GitHubowasp/owaspbugbounty

This is a container of web applications that work with OWASP Bug Bounty for Projects

ctfeducationlabs-practice+3
341 year ago
drupal-cve-2018-7600-poc preview

drupal-cve-2018-7600-poc

GitHubdowonkwon/drupal-cve-2018-7600-poc

Proof-of-concept exploit for CVE-2018-7600 (Drupalgeddon 2) with a step-by-step lab environment setup and exploitation walkthrough using Docker and…

educationexploitationlabs-practice+3
1 year ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubraytran54/cve-2018-7600

Step-by-step analysis and exploitation lab for Drupal CVE-2018-7600 remote code execution vulnerability, including debugging, exploit code, and…

code-analysiseducationexploitation+3
2 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubyrkuo/cve-2022-30190

Step-by-step reproduction guide for CVE-2022-30190 (Follina) MSDT remote code execution vulnerability, including malicious document creation and C2…

educationexploitationlabs-practice+3
3 years ago
Struts2Vuln preview

Struts2Vuln

GitHubmike-williams/struts2vuln

Struts 2 web app that is vulnerable to CVE-2017-98505 and CVE-2017-5638

educationexploitationlabs-practice+3
19 years ago
Next.js-Middleware-Bypass-CVE-2025-29927- preview

Next.js-Middleware-Bypass-CVE-2025-29927-

GitHubpouriam23/next.js-middleware-bypass-cve-2025-29927-

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

ctfeducationlabs-practice+3
21 year ago
lab-cve-2025-3515 preview

lab-cve-2025-3515

GitHubimbios/lab-cve-2025-3515

CVE-2025-3515 WordPress lab for Drag and Drop Multiple File Upload for CF7: Dockerized PoC & Nuclei testing

educationexploitationlabs-practice+2
11 year ago
lab-cve-2016-15042 preview

lab-cve-2016-15042

GitHubimbios/lab-cve-2016-15042

CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1

ctfeducationlabs-practice+3
11 year ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

command-and-controldefensive-toolseducation+8
13 years ago
CVE-2024-5084-Red-Team preview

CVE-2024-5084-Red-Team

GitHubredteamblueteam/cve-2024-5084-red-team

Proof-of-concept exploit for CVE-2024-5084 (Hash Form WordPress plugin) demonstrating unauthenticated file upload to RCE. Designed for educational…

educationexploitationlabs-practice+4
17 months ago
Previous12Next