Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
EXPLOIT-CVE-2026-42559 preview

EXPLOIT-CVE-2026-42559

GitHubjoaovicdev/exploit-cve-2026-42559

Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport

educationexploitationlabs-practice+2
1 day ago
CVE-2026-42559 preview

CVE-2026-42559

GitHubjoaovicdev/cve-2026-42559

Docker lab and Python proof-of-concept demonstrating DNS rebinding via unvalidated Host header in rmcp Streamable HTTP server transport…

educationexploitationlabs-practice+2
1 day ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

educationexploitationlabs-practice+3
24 days ago
log4shell-cve-lab preview

log4shell-cve-lab

GitHubvaibhav91one/log4shell-cve-lab

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

educationexploitationlabs-practice+2
8 days ago
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

api-security-testingeducationexploitation+4
16 days ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

educationexploitationlabs-practice+4
19 days ago
CVE-2023-25690_lab preview

CVE-2023-25690_lab

GitHubgiordy0424/cve-2023-25690_lab

HTTP Request Smuggling lab: Apache 2.4.55 CRLF injection

ctfeducationlabs-practice+3
21 days ago
CVE-2021-41773-Exploit-Lab preview

CVE-2021-41773-Exploit-Lab

GitHubsanr01/cve-2021-41773-exploit-lab

CVE-2021-41773 Exploit Lab

educationexploitationlabs-practice+4
24 days ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubemaar1x/cve-2021-41773

Educational Docker lab for Apache HTTP Server 2.4.49 path traversal and RCE (CVE-2021-41773) with CVE research, PoC exploit, testing evidence, and…

educationexploitationlabs-practice+4
24 days ago
CVE-2021-41773-Apache-Lab preview

CVE-2021-41773-Apache-Lab

GitHubs-amnajafri/cve-2021-41773-apache-lab

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

educationexploitationlabs-practice+4
25 days ago
BSCP-EXAM-GUIDE-BY-N3OARI-2026 preview

BSCP-EXAM-GUIDE-BY-N3OARI-2026

GitHubn3oari/bscp-exam-guide-by-n3oari-2026

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

curated-resourceseducationlabs-practice+3
2928 days ago
cve-2021-41773-source-code-analysis preview

cve-2021-41773-source-code-analysis

GitHubkunalkhandelwal-dev/cve-2021-41773-source-code-analysis

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

code-analysiseducationlabs-practice+2
1 month ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubtr3m0x/cve-2021-41773

PoC and analysis of CVE-2021-41773

educationlabs-practicepenetration-testing+3
1 month ago
apache-cve-2021-42013-lab preview

apache-cve-2021-42013-lab

GitHubberraesen/apache-cve-2021-42013-lab

Docker ortamında Apache HTTP Server 2.4.49 (CVE-2021-42013) zafiyetinin gösterildiği laboratuvar çalışması.

container-securityeducationexploitation+3
1 month ago
Apache-CVE-2021-41773 preview

Apache-CVE-2021-41773

GitHublheeeesoo/apache-cve-2021-41773

WHS 4기 이희수. kr-vulhub 과제 제출물

educationexploitationlabs-practice+3
1 month ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubjohnwickakash12/cve-2021-41773

Detailed writeup of CVE-2021-41773 Apache path traversal and RCE exploitation, with step-by-step commands and root cause analysis from a TryHackMe…

ctfeducationexploitation+3
2 months ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubeunho87/cve-2021-42013

Proof-of-concept exploit for CVE-2021-42013 Apache HTTP Server path traversal and remote code execution vulnerability, with Docker-based lab…

educationexploitationlabs-practice+3
2 months ago
CVE-2026-44789-n8n-PrototypePollution-RCE preview

CVE-2026-44789-n8n-PrototypePollution-RCE

GitHubbiitts/cve-2026-44789-n8n-prototypepollution-rce

CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified…

code-analysiseducationexploitation+5
2 months ago
Previous1234Next