Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
DamnVulnerableCryptoApp preview

DamnVulnerableCryptoApp

GitHubdamnvulnerablecryptoapp/damnvulnerablecryptoapp

An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about…

cryptographyeducationlabs-practice+1
86
4 years ago
CVE-2023-38408 preview

CVE-2023-38408

GitHubkali-mx/cve-2023-38408

PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2

ctfeducationexploitation+3
531 year ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubrandengshifu/cve-2022-22963

CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit

educationexploitationlabs-practice+2
154 years ago
cve-2026-71362-magento-lab preview

cve-2026-71362-magento-lab

GitHubdinosn/cve-2026-71362-magento-lab

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

authentication-authorizationeducationexploitation+4
51 month ago
NORM-EDR preview

NORM-EDR

GitHubamberchalia/norm-edr

Experimental kernel-mode EDR research project focused on explainable detection of suspicious in-memory execution patterns, producing human-readable…

binary-analysisdefensive-toolseducation+4
116 months ago
security-writeups preview

security-writeups

GitHubalzeaty1/security-writeups

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

ctfeducationlabs-practice+5
3 days ago
CVE-2024-1813-POC preview

CVE-2024-1813-POC

GitHubmobetasec/cve-2024-1813-poc

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

ctfeducationlabs-practice+4
2 months ago
android-workprofile-exploit preview

android-workprofile-exploit

GitHubhasan-al-hussein/android-workprofile-exploit

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

android-securitydata-exfiltrationeducation+5
12 months ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

command-and-controldefensive-toolseducation+8
13 years ago
Next.js-Middleware-Bypass-CVE-2025-29927- preview

Next.js-Middleware-Bypass-CVE-2025-29927-

GitHubpouriam23/next.js-middleware-bypass-cve-2025-29927-

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

ctfeducationlabs-practice+3
21 year ago
CVE-2022-30190-Follina-Lab preview

CVE-2022-30190-Follina-Lab

GitHubu1tr0nex/cve-2022-30190-follina-lab

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

command-and-controleducationexploitation+7
4 months ago
Struts2Vuln preview

Struts2Vuln

GitHubmike-williams/struts2vuln

Struts 2 web app that is vulnerable to CVE-2017-98505 and CVE-2017-5638

educationexploitationlabs-practice+3
19 years ago
lab-cve-2025-3515 preview

lab-cve-2025-3515

GitHubimbios/lab-cve-2025-3515

CVE-2025-3515 WordPress lab for Drag and Drop Multiple File Upload for CF7: Dockerized PoC & Nuclei testing

educationexploitationlabs-practice+2
11 year ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubyrkuo/cve-2022-30190

Step-by-step reproduction guide for CVE-2022-30190 (Follina) MSDT remote code execution vulnerability, including malicious document creation and C2…

educationexploitationlabs-practice+3
3 years ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubraytran54/cve-2018-7600

Step-by-step analysis and exploitation lab for Drupal CVE-2018-7600 remote code execution vulnerability, including debugging, exploit code, and…

code-analysiseducationexploitation+3
2 years ago
CVE-2020-7699_reproduce preview

CVE-2020-7699_reproduce

GitHubzodiac12-pub/cve-2020-7699_reproduce

针对 CVE-2020-7699 的复现,软件安全原理课程大作业

educationexploitationlabs-practice+3
4 years ago
drupal-cve-2018-7600-poc preview

drupal-cve-2018-7600-poc

GitHubdowonkwon/drupal-cve-2018-7600-poc

Proof-of-concept exploit for CVE-2018-7600 (Drupalgeddon 2) with a step-by-step lab environment setup and exploitation walkthrough using Docker and…

educationexploitationlabs-practice+3
1 year ago
Previous12Next