Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
93 results
CVE-2021-34527 preview

CVE-2021-34527

GitHubdenizse/cve-2021-34527

Small Powershell Script to detect Running Printer Spoolers on Domain Controller

educationexploitationinformation-gathering+3
5 years ago
HTB-NanoCorp-CVE-2024-0670 preview

HTB-NanoCorp-CVE-2024-0670

GitHubdfdxarjy/htb-nanocorp-cve-2024-0670

PowerShell exploit for CVE-2024-0670, abusing CheckMK Agent MSI repair to escalate from low-privileged user to SYSTEM on Windows targets. Designed…

binary-exploitationctfeducation+5
2 months ago
deploy-goad preview

deploy-goad

GitHublkarlslund/deploy-goad

Script to install prerequisites for deploying GOAD on Ubuntu Linux 22.04

educationlabs-practicepenetration-testing+1
1162 years ago
cve-2021-42013 preview

cve-2021-42013

GitHubwalnutsecurity/cve-2021-42013

cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50

exploitationlabs-practicepenetration-testing+3
273 years ago
CVE-2025-1094-PoC-Postgre-SQLi preview

CVE-2025-1094-PoC-Postgre-SQLi

GitHubishwardeepp/cve-2025-1094-poc-postgre-sqli

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

code-analysisdatabase-securityeducation+5
61 year ago
CVE-2020-8163 preview

CVE-2020-8163

GitHubh4ms1k/cve-2020-8163

Docker-based lab environment and exploit script for CVE-2020-8163, a blind remote code execution vulnerability in Rails versions before 5.0.1 and…

educationexploitationlabs-practice+3
46 years ago
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

api-security-testingeducationexploitation+4
12 days ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubr4y-br/cve-2022-22963

Python automation script that reproduces CVE-2022-22963, a critical SpEL injection in Spring Cloud Function, enabling reverse shell in authorized lab…

ctfeducationexploitation+3
13 days ago
CVE-2026-17532-lab preview

CVE-2026-17532-lab

GitHubkalhoralireza/cve-2026-17532-lab

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

educationexploitationlabs-practice+3
9 days ago
CVE-2026-21877 preview

CVE-2026-21877

GitHubcves-labs/cve-2026-21877

Dockerized vulnerable lab environment with a Python-based network monitor and dedicated exploit script, enabling hands-on exploitation, privilege…

ctfeducationexploitation+3
21 days ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubpedrorichil/cve-2025-49844

Educational lab environment demonstrating CVE-2025-49844 (RediShell) in Redis. Includes Docker setup, exploit PoC script, and security…

educationexploitationlabs-practice+3
611 months ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubyeonchoda/cve-2024-9264

PoC exploit for CVE-2024-9264: Grafana SQL Expression vulnerability enabling local file inclusion and remote code execution via DuckDB SQL injection.…

educationexploitationlabs-practice+3
2 months ago
Learn-about-cve-2025-31133-poc preview

Learn-about-cve-2025-31133-poc

GitHubc-h4ck-0/learn-about-cve-2025-31133-poc

Educational proof-of-concept for CVE-2025-31133, a runc container escape via maskedPaths race condition. Includes lab setup, exploit script, and…

container-escapecontainer-securityeducation+3
25 months ago
CVE-2021-44228-white-box preview

CVE-2021-44228-white-box

GitHubhotpotcookie/cve-2021-44228-white-box

Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting…

educationexploitationlabs-practice+3
32 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubdungsocool/cve-2024-23897

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

educationexploitationlabs-practice+2
1 month ago
CVE-2026-8206-Lab preview

CVE-2026-8206-Lab

GitHubrootdirective-sec/cve-2026-8206-lab

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…

ctfeducationexploitation+3
3 months ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubeunho87/cve-2021-42013

Proof-of-concept exploit for CVE-2021-42013 Apache HTTP Server path traversal and remote code execution vulnerability, with Docker-based lab…

educationexploitationlabs-practice+3
1 month ago
CVE-2024-23897-Vulnerabilidad-Jenkins preview

CVE-2024-23897-Vulnerabilidad-Jenkins

GitHubd1se0/cve-2024-23897-vulnerabilidad-jenkins

Python exploit script for CVE-2024-23897 (Jenkins RCE) with an automated Docker-based vulnerable lab for controlled security testing and education.

educationexploitationlabs-practice+2
41 year ago
Previous123456Next