Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
787 results
activemq-ids-ips-lab preview

activemq-ids-ips-lab

GitHubtrnguyen03/activemq-ids-ips-lab

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

educationexploit-frameworksids-ips-evasion+6
4 months ago
CVE-2024-5084-Red-Team preview

CVE-2024-5084-Red-Team

GitHubredteamblueteam/cve-2024-5084-red-team

Proof-of-concept exploit for CVE-2024-5084 (Hash Form WordPress plugin) demonstrating unauthenticated file upload to RCE. Designed for educational…

educationexploitationlabs-practice+4
17 months ago
cve-2018-11776 preview

cve-2018-11776

GitHubcved-sources/cve-2018-11776

Docker container providing a vulnerable Apache Struts2 environment for CVE-2018-11776 exploitation practice and security education.

container-securityeducationexploitation+3
15 years ago
NextJS-app-CVE-2025-55182 preview

NextJS-app-CVE-2025-55182

GitHubs-mughal/nextjs-app-cve-2025-55182

Proof-of-concept Next.js application demonstrating CVE-2025-55182 (React2Shell), a critical RCE in React Server Components, with exploit example and…

educationexploitationlabs-practice+3
8 months ago
n8n-RCE-CVE-2025-68613 preview

n8n-RCE-CVE-2025-68613

GitHubahmedshamsddin/n8n-rce-cve-2025-68613

n8n RCE (CVE-2025-68613)

educationexploitationlabs-practice+3
7 months ago
CVE-2025-32463_sudo_chroot preview

CVE-2025-32463_sudo_chroot

GitHublowercasenumbers/cve-2025-32463_sudo_chroot

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo's chroot feature via malicious NSS library loading. Includes…

binary-exploitationeducationexploitation+3
9 months ago
CVE-2025-55182-Dockerized preview

CVE-2025-55182-Dockerized

GitHubclevernyyyy/cve-2025-55182-dockerized

Dockerized proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components via prototype pollution, with automated exploit scripts and…

educationexploitationlabs-practice+3
16 months ago
cve-images preview

cve-images

GitHubedgecases-purplehax/cve-images

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

container-securityctfcurated-resources+5
13 months ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xnxt1me/cve-2025-29927

Proof-of-concept exploit for CVE-2025-29927 that adds x-middleware-subrequest to bypass Next.js middleware authentication checks.

authentication-authorizationeducationlabs-practice+3
11 year ago
cve-2019-10678 preview

cve-2019-10678

GitHubcved-sources/cve-2019-10678

Docker container providing a vulnerable environment for CVE-2019-10678, designed for security training and exploitation practice within the Cved…

container-securityeducationexploitation+2
15 years ago
CVE-2018-7602 preview

CVE-2018-7602

GitHubkastellanos/cve-2018-7602

Drupalgeddon3 RCE exploit lab with Docker-based vulnerable environment and Metasploit integration for hands-on CVE-2018-7602 exploitation training.

educationexploitationlabs-practice+3
17 years ago
CVE-2022-21907 preview

CVE-2022-21907

GitHubkamal-marouane/cve-2022-21907

Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash.

educationexploitationlabs-practice+2
12 years ago
CVE-2025-54309__Enhanced_exploit preview

CVE-2025-54309__Enhanced_exploit

GitHubwhisperer1290/cve-2025-54309__enhanced_exploit

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

authentication-authorizationeducationexploitation+4
11 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubalastair66/cve-2025-29927

Next.js Middleware Bypass Vulnerability

educationexploitationlabs-practice+3
11 year ago
Libssh2-Exploit preview

Libssh2-Exploit

GitHubviz27/libssh2-exploit

Create an exploit to libssh2 vulnerabulity described in CVE-2019-13115

binary-exploitationeducationexploitation+3
16 years ago
mongobleed preview

mongobleed

GitHubadolfbharath/mongobleed

CVE-2025-14847 explaination and lab

cryptographydatabase-securityeducation+3
18 months ago
offensive-security-adversary-emulation preview

offensive-security-adversary-emulation

GitHubkhalilu020/offensive-security-adversary-emulation

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

educationexploitationlabs-practice+5
1 month ago
CVE-2022-0185-POC preview

CVE-2022-0185-POC

GitHubprabeershakya/cve-2022-0185-poc

Proof-of-concept exploit for CVE-2022-0185, a Linux kernel heap buffer overflow enabling local privilege escalation and container escape via FUSE and…

binary-exploitationcontainer-escapeeducation+4
6 months ago
Previous1…373839…44Next