Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
587 results
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
21 days ago
CVE-2026-63223-POC preview

CVE-2026-63223-POC

GitHubimbas007/cve-2026-63223-poc

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

educationexploitationlabs-practice+5
118 days ago
gitea-CVE-2026-28699 preview

gitea-CVE-2026-28699

GitHubalardiians/gitea-cve-2026-28699

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

authentication-authorizationctfeducation+5
12 months ago
cve-2025-66398 preview

cve-2025-66398

GitHubjoshuavanderpoll/cve-2025-66398

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

command-and-controleducationexploitation+7
25 months ago
pocketbase-CVE-2026-44166 preview

pocketbase-CVE-2026-44166

GitHubalardiians/pocketbase-cve-2026-44166

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

authenticationctfeducation+5
2 months ago
SUDO_KILLER preview

SUDO_KILLER

GitHubth3xace/sudo_killer

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

ctfeducationexploitation+5
2.5k5 months ago
Awesome-CloudSec-Labs preview

Awesome-CloudSec-Labs

GitHubiknowjason/awesome-cloudsec-labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

cloud-securitycontainer-securityctf+7
2.2k10 months ago
mutillidae preview

mutillidae

GitHubwebpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

ctfeducationlabs-practice+3
1.5k1 month ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
91810 months ago
CVE-2023-25690-POC preview

CVE-2023-25690-POC

GitHubdhmosfunk/cve-2023-25690-poc

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

educationexploitationlabs-practice+3
2891 year ago
ctf-screenshotter preview

ctf-screenshotter

GitHubliveoverflow/ctf-screenshotter

CTF web challenge simulating a real-world screenshotting vulnerability, with Docker setup and video writeup for hands-on security education.

ctfeducationlabs-practice+1
2245 years ago
lazyweb preview

lazyweb

GitHubramadhanamizudin/lazyweb

LazyWeb is a demonstration web application designed to showcase common server-side application vulnerabilities. Each vulnerability is categorized…

educationlabs-practicepenetration-testing+2
1281 year ago
CVE-2021-22204-exiftool preview

CVE-2021-22204-exiftool

GitHubconvisolabs/cve-2021-22204-exiftool

Python exploit for the CVE-2021-22204 vulnerability in Exiftool

educationexploitationlabs-practice+2
965 years ago
xss_vulnerability_challenges preview

xss_vulnerability_challenges

GitHubmoeinfatehi/xss_vulnerability_challenges

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

educationlabs-practicepenetration-testing+3
1194 years ago
CVE-2025-8088-Winrar-Tool preview

CVE-2025-8088-Winrar-Tool

GitHubhexsecteam/cve-2025-8088-winrar-tool

A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5…

educationexploitationlabs-practice+5
4811 months ago
AndroidKernelVulnerability preview

AndroidKernelVulnerability

GitHubsharif-dev/androidkernelvulnerability

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

android-securitybinary-exploitationdynamic-analysis-sandboxing+5
723 years ago
HazProne preview

HazProne

GitHubstafordtituss/hazprone

Cloud pentesting framework deploying vulnerable-by-demand AWS resources with quest-based scenarios to teach practical penetration testing and…

cloud-securityeducationlabs-practice+2
404 years ago
android-kernel-exploitation-lab preview

android-kernel-exploitation-lab

GitHub0xbinder/android-kernel-exploitation-lab

This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.

android-securitybinary-exploitationdebuggers+6
431 year ago
Previous1234…33Next