Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
CVE-2026-9086-poc preview

CVE-2026-9086-poc

GitHubsaku0512/cve-2026-9086-poc

CVE-2026-9086 proof-of-concept for Keycloak client URI validation bypass using mixed-case javascript: and data: XSS payloads, with Docker-based…

educationexploitationlabs-practice+3
1
1 month ago
CVE-2025-11262-Lab preview

CVE-2025-11262-Lab

GitHubrootdirective-sec/cve-2025-11262-lab

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

ctfeducationlabs-practice+3
3 months ago
CVE-2014-3120 preview

CVE-2014-3120

GitHubdungsocool/cve-2014-3120

Step-by-step lab guide demonstrating CVE-2014-3120 exploitation against Elasticsearch 1.1.1, covering vulnerability analysis, RCE via MVEL scripting,…

container-securityeducationexploitation+3
3 months ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubzaidarif47/cve-2024-42009

Docker-based proof-of-concept for CVE-2024-42009, a stored XSS in Roundcube Webmail. Demonstrates exploitation via crafted HTML emails and includes…

educationexploitationlabs-practice+3
15 months ago
leaflet-cve-2025-69993 preview

leaflet-cve-2025-69993

GitHubpierfrancescoconti/leaflet-cve-2025-69993

Proof-of-concept for CVE-2025-69993: Cross-Site Scripting in Leaflet's bindPopup() method. Includes advisory, impact analysis, and a demo Angular…

educationlabs-practicevulnerability-analysis+2
5 months ago
Email-exploit-Moniker-Link-CVE-2024-21413- preview

Email-exploit-Moniker-Link-CVE-2024-21413-

GitHubyass2400012/email-exploit-moniker-link-cve-2024-21413-

Proof-of-concept exploit for CVE-2024-21413 using Moniker Link in HTML email to trigger SMB connection and capture netNTLMv2 hashes via Responder.…

educationemail-securityexploitation+6
1 year ago
CVE-2021-24891-Simulation preview

CVE-2021-24891-Simulation

GitHubhackmelocal/cve-2021-24891-simulation

Containerized lab environment to simulate and exploit a DOM-based XSS vulnerability (CVE-2021-24891) in the Elementor WordPress plugin for hands-on…

ctfeducationlabs-practice+3
1 year ago
CVE-2024-46538 preview

CVE-2024-46538

GitHublauleysen/cve-2024-46538

based on [EQSTLab](https://github.com/EQSTLab)

educationexploitationlabs-practice+3
41 year ago
CVE-2012-2982 preview

CVE-2012-2982

GitHubcpyre/cve-2012-2982

Practice POC scripting in Tryhackme’s intro poc scripting room (For Linux)

educationexploitationlabs-practice+3
2 years ago
Exploite-CVE-2023-30212-vulnerability preview

Exploite-CVE-2023-30212-vulnerability

GitHublibasv/exploite-cve-2023-30212-vulnerability

Docker-based lab environment to exploit CVE-2023-30212, a cross-site scripting (XSS) vulnerability in OURPHP <= 7.2.0, with step-by-step setup and…

container-securityeducationexploitation+3
3 years ago
Exploite-CVE-2023-30212-Vulnerability preview

Exploite-CVE-2023-30212-Vulnerability

GitHublibasmon/exploite-cve-2023-30212-vulnerability

Docker environment and exploit the CVE-2023-30212 vulnerabilityVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or…

container-securityeducationexploitation+3
43 years ago
-create-a-vulnerable-Docker-environment-that-is-susceptible-to-CVE-2023-30212 preview

-create-a-vulnerable-Docker-environment-that-is-susceptible-to-CVE-2023-30212

GitHublibasmon/-create-a-vulnerable-docker-environment-that-is-susceptible-to-cve-2023-30212

Docker environment and exploit the CVE-2023-30212 vulnerabilityVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or…

container-securityeducationexploitation+3
3 years ago
CVE-2023-30212 preview

CVE-2023-30212

GitHublibas7994/cve-2023-30212

Docker environment and exploit the CVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or equal to 7.2.0 .This…

educationexploitationlabs-practice+2
3 years ago
CVE-2012-2982 preview

CVE-2012-2982

GitHub0xtas/cve-2012-2982

Exploits CVE-2012-2982 in Webmin with a Rust PoC that delivers a configurable TCP reverse shell and optional Netcat listener.

educationexploitationlabs-practice+3
33 years ago
0l4bs preview

0l4bs

GitHubtegal1337/0l4bs

Cross-site scripting labs for web application security enthusiasts

ctfeducationlabs-practice+1
3485 years ago
XSSChallengeWiki preview
Archived

XSSChallengeWiki

GitHubcure53/xsschallengewiki

Community-maintained wiki cataloging XSS challenges and solutions, providing curated hands-on exercises for learning cross-site scripting…

ctfcurated-resourceseducation+5
1.6k6 years ago