Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
791 results
CVE-2021-41773-Exploit-Lab preview

CVE-2021-41773-Exploit-Lab

GitHubsanr01/cve-2021-41773-exploit-lab

CVE-2021-41773 Exploit Lab

educationexploitationlabs-practice+4
24 days ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
25 days ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubshivshantp/cve-2025-24813

Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC

educationexploitationlabs-practice+5
51 year ago
traefik-stripprefix-auth-bypass-cve-2026-48020-path-normalization preview

traefik-stripprefix-auth-bypass-cve-2026-48020-path-normalization

GitHubhunt-benito/traefik-stripprefix-auth-bypass-cve-2026-48020-path-normalization

Proof-of-concept lab for CVE-2026-48020, demonstrating a critical auth bypass in Traefik's StripPrefix middleware via path normalization. Includes…

educationexploitationlabs-practice+3
2 months ago
CVE-2025-8088 preview

CVE-2025-8088

GitHubwalidpyh/cve-2025-8088

Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab…

binary-exploitationeducationexploitation+2
41 year ago
CVE-2026-39808 preview

CVE-2026-39808

GitHub0xblackash/cve-2026-39808

CVE-2026-39808

command-and-controleducationexploitation+5
24 months ago
zero-click-exploit-analysis preview

zero-click-exploit-analysis

GitHubdanielw98/zero-click-exploit-analysis

CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

binary-exploitationeducationexploitation+7
33 months ago
CVE-2023-2640-CVE-2023-32629-Interactive-PoC preview

CVE-2023-2640-CVE-2023-32629-Interactive-PoC

GitHubamar-imamovic/cve-2023-2640-cve-2023-32629-interactive-poc

A clean, interactive multi-step Local Privilege Escalation (LPE) exploit for Ubuntu OverlayFS (GameOver(lay)) that escapes the user namespace sandbox…

educationexploitationlabs-practice+3
2 months ago
CVE-2026-55255-Lab preview

CVE-2026-55255-Lab

GitHubrootdirective-sec/cve-2026-55255-lab

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

api-security-testingeducationlabs-practice+3
2 months ago
PoC-2023-43208 preview

PoC-2023-43208

GitHubmkirahmet/poc-2023-43208

A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.

educationexploitationlabs-practice+3
36 months ago
cve-2018-7600-drupalgeddon2-lab preview

cve-2018-7600-drupalgeddon2-lab

GitHubmeraj1312/cve-2018-7600-drupalgeddon2-lab

Educational lab demonstrating CVE-2018-7600 (Drupalgeddon2) Remote Code Execution using a Docker-based vulnerable Drupal 7.56 environment.

ctfeducationexploitation+5
15 months ago
CVE-2023-21554 preview

CVE-2023-21554

GitHubshootweb/cve-2023-21554

CVE-2023-21554 PoC

educationexploitationlabs-practice+3
211 months ago
vaas-cve-2015-5477 preview

vaas-cve-2015-5477

GitHubhmlio/vaas-cve-2015-5477

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

container-securitydns-analysiseducation+3
111 years ago
CVE-2025-1913-PoC preview

CVE-2025-1913-PoC

GitHubs0haib518-ksa/cve-2025-1913-poc

A PoC demonstrating CVE-2025-1913, showing how the plugin’s unsafe unserialize handling can lead to high-impact behavior in controlled environments.…

educationexploitationlabs-practice+3
28 months ago
CVE-2024-36039_PoC preview

CVE-2024-36039_PoC

GitHubzenniskayy2k4/cve-2024-36039_poc

PoC for CVE-2024-36039: Demonstrating SQL Injection via PyMySQL Object-to-String serialization flaw

database-securityeducationexploitation+3
15 months ago
linux-copy-fail-CVE-2026-31431 preview

linux-copy-fail-CVE-2026-31431

GitHubadilkurtulmus/linux-copy-fail-cve-2026-31431

Proof-of-concept exploit for CVE-2026-31431 (Copy-Fail), a Linux kernel AF_ALG and splice() flaw enabling page cache poisoning and local privilege…

binary-exploitationeducationexploitation+4
3 months ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubelrajiii/cve-2025-5548

Buffer overflow in FreeFloat FTP Server 1.0

binary-exploitationdebuggerseducation+8
5 months ago
ghostcat-verification preview

ghostcat-verification

GitHubshaunmclernon/ghostcat-verification

Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)

educationexploitationlabs-practice+2
16 years ago
Previous1…567…44Next