Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
587 results
cve-2025-29927-demo preview

cve-2025-29927-demo

GitHubt3tra-dev/cve-2025-29927-demo

Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。

authentication-authorizationeducationlabs-practice+2
4
1 year ago
CVEsLab preview

CVEsLab

GitHubsecuritrust/cveslab

💀 A collection of proof-of-concept exploit scripts on docker lab environments has been discovered by Securi Trust Team. Vulnerabilities has been…

educationexploitationlabs-practice+2
14 years ago
poc-cve-2019-14287 preview

poc-cve-2019-14287

GitHublemonadern/poc-cve-2019-14287
container-securityeducationexploitation+3
1 year ago
CVE-2023-50164Analysis- preview

CVE-2023-50164Analysis-

GitHubasfandalimemon25/cve-2023-50164analysis-

CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a…

educationexploitationlabs-practice+3
2 years ago
DeliberatelyVulnerableWebApp preview
Archived

DeliberatelyVulnerableWebApp

GitHubtimothyjxhn/deliberatelyvulnerablewebapp

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

educationexploitationlabs-practice+3
1 year ago
poc-cve-2025-55182 preview

poc-cve-2025-55182

GitHubkoadt/poc-cve-2025-55182

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

code-analysisctfdynamic-analysis-sandboxing+7
155 months ago
SpringBreakVulnerableApp preview

SpringBreakVulnerableApp

GitHubm3ssap0/springbreakvulnerableapp

WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!

educationexploitationlabs-practice+3
147 years ago
CVE-2026-2587-Exploit-POC preview

CVE-2026-2587-Exploit-POC

GitHubbhanunamikaze/cve-2026-2587-exploit-poc

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

code-analysisdynamic-analysis-sandboxingeducation+6
13 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubl4rm4nd/cve-2025-55182

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

educationlabs-practicepenetration-testing+4
868 months ago
CVE-2025-32463_chwoot preview

CVE-2025-32463_chwoot

GitHubashardev002/cve-2025-32463_chwoot

🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.

container-securityeducationexploitation+3
11 day ago
CVE-2026-40048 preview

CVE-2026-40048

GitHuboscerd/cve-2026-40048

Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)

binary-exploitationcode-analysiseducation+6
1 month ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubmayca369/cve-2025-55182

Demonstrates CVE-2025-55182 RCE exploit in React Server Functions to highlight insecure prototype references in Next.js, with educational simulation…

educationexploitationlabs-practice+3
8 days ago
h4cker preview

h4cker

GitHubthe-art-of-hacking/h4cker

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

ai-securityctfcurated-resources+5
29.1k6 days ago
Damn-Vulnerable-GraphQL-Application preview

Damn-Vulnerable-GraphQL-Application

GitHubdolevf/damn-vulnerable-graphql-application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

api-securityapi-security-testingctf+5
1.7k1 year ago
fastjson-jsontype-rce-lab preview

fastjson-jsontype-rce-lab

GitHubdinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

dynamic-analysis-sandboxingeducationexploitation+5
20424 days ago
CVE-2026-50416-writeup-and-poc preview

CVE-2026-50416-writeup-and-poc

GitHubkarollooool/cve-2026-50416-writeup-and-poc

CVE-2026-50416: Windows 11 KASLR bypass

binary-analysisctfeducation+7
448 days ago
CVE-2024-46538 preview

CVE-2024-46538

GitHubeqstlab/cve-2024-46538

PfSense Stored XSS lead to Arbitrary Code Execution exploit

educationexploitationlabs-practice+3
501 year ago
cve-2016-1000027-poc preview

cve-2016-1000027-poc

GitHubartem-smotrakov/cve-2016-1000027-poc

PoC for CVE-2016-1000027

educationexploitationlabs-practice+3
125 years ago
Previous123…33Next