Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
CVE-2025-32463_sudo_chroot preview

CVE-2025-32463_sudo_chroot

GitHublowercasenumbers/cve-2025-32463_sudo_chroot

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo's chroot feature via malicious NSS library loading. Includes…

binary-exploitationeducationexploitation+3
9 months ago
BIND-9-Cache-Poisoning-PoC---CVE-2025-40778 preview

BIND-9-Cache-Poisoning-PoC---CVE-2025-40778

GitHubsirbuvladste/bind-9-cache-poisoning-poc---cve-2025-40778

Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records.

dns-analysiseducationexploitation+3
8 months ago
winrar_CVE-2023-38831_lazy_poc preview

winrar_CVE-2023-38831_lazy_poc

GitHubboredhackerblog/winrar_cve-2023-38831_lazy_poc

lazy way to create CVE-2023-38831 winrar file for testing

educationexploitationlabs-practice+2
913 years ago
CVE-2026-12191 preview

CVE-2026-12191

GitHubhakaioffsec/cve-2026-12191

PoC for CVE-2026-12191

binary-exploitationcode-analysiseducation+3
51 month ago
CVE-2021-34824 preview

CVE-2021-34824

GitHubrsalmond/cve-2021-34824

reproducing an old istio bug

cloud-securityeducationlabs-practice+2
3 years ago
CVE-2025-8088-Winrar-Tool preview

CVE-2025-8088-Winrar-Tool

GitHubhexsecteam/cve-2025-8088-winrar-tool

A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5…

educationexploitationlabs-practice+5
481 year ago
CVE-2025-6218_WinRAR preview

CVE-2025-6218_WinRAR

GitHubspeinador/cve-2025-6218_winrar

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite…

binary-exploitationeducationexploitation+3
161 year ago
cve-2023-51385 preview

cve-2023-51385

GitHublsp1025923/cve-2023-51385

Reproduction lab for CVE-2023-51385: command injection in OpenSSH ProxyCommand via malicious git submodule URLs. Step-by-step guide to verify the…

educationexploitationlabs-practice+2
2 months ago
Laravel-CVE-2018-15133 preview

Laravel-CVE-2018-15133

GitHubyeahhbean/laravel-cve-2018-15133

Docker-based PoC environment for CVE-2018-15133 Laravel APP_KEY unserialization vulnerability. Includes exploit script to verify remote code…

educationexploitationlabs-practice+3
21 year ago
CVE-2022-28346 preview

CVE-2022-28346

GitHubkamal-marouane/cve-2022-28346

A flaw was found in the Django package, which leads to a SQL injection. This flaw allows an attacker using a crafted dictionary containing malicious…

database-securityeducationexploitation+3
12 years ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

command-and-controldefensive-toolseducation+8
13 years ago
CVE-2021-44228_Log4Shell preview

CVE-2021-44228_Log4Shell

GitHubvutiendat323/cve-2021-44228_log4shell

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

educationexploitationlabs-practice+3
3 months ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubdanilo1992-sys/cve-2021-29447

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

educationexploitationlabs-practice+3
5 months ago
cve-2025-54988-VulnTikaProject preview

cve-2025-54988-VulnTikaProject

GitHubgaloryber/cve-2025-54988-vulntikaproject

Deliberately vulnerable Spring Boot application using Apache Tika 3.2.1 for testing CVE-2025-54988 XXE exploitation via malicious PDF uploads.

educationexploitationlabs-practice+3
8 months ago
CVE-2023-38831_ReverseShell_Winrar preview

CVE-2023-38831_ReverseShell_Winrar

GitHubben1b3astt/cve-2023-38831_reverseshell_winrar

Generates a malicious RAR archive exploiting CVE-2023-38831 to deliver a reverse shell via a crafted PDF, for ethical testing in controlled…

educationexploitationlabs-practice+3
13 years ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
Tika-CVE-2025-66516-Lab preview

Tika-CVE-2025-66516-Lab

GitHubintsheep/tika-cve-2025-66516-lab

Minimal verification lab for CVE-2025-66516 (Apache Tika XXE). Generates malicious PDF payloads and validates the vulnerability by reading sensitive…

educationexploitationlabs-practice+3
8 months ago
CVE-2023-51385_test preview

CVE-2023-51385_test

GitHubfeatherw1t/cve-2023-51385_test

Proof-of-concept for CVE-2023-51385: demonstrates command injection via malicious git submodule URLs when cloning with --recurse-submodules,…

educationexploitationlabs-practice+2
2 years ago
Previous123Next