Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
941 results
vulnerable-bsr-lab-CVE-2023-6933 preview

vulnerable-bsr-lab-CVE-2023-6933

GitHubtrex96/vulnerable-bsr-lab-cve-2023-6933

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

educationexploit-frameworkslabs-practice+3
11 months ago
sk-cve-2026-26030-lab preview

sk-cve-2026-26030-lab

GitHubinertfluid/sk-cve-2026-26030-lab

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

ai-securitybinary-exploitationeducation+5
12 months ago
CVE-2018-1058 preview

CVE-2018-1058

GitHubccchme/cve-2018-1058

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

database-securityeducationexploitation+3
3 months ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubj3r1ch0123/cve-2025-9074

New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet

container-securityeducationexploitation+3
80 years ago
cve-2025-55182 preview

cve-2025-55182

GitHubps-interactive/cve-2025-55182

Vulnerable REACT app in docker container and poc code - for demos

container-securityeducationexploitation+4
8 months ago
Trickster-HTB preview

Trickster-HTB

GitHubpallangyo98/trickster-htb

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

ctfeducationexploitation+5
1 year ago
CVE-2025-29927-Nextjs-Analysis preview

CVE-2025-29927-Nextjs-Analysis

GitHubsangrok-jeon/cve-2025-29927-nextjs-analysis

CVE-2025-29927-Nextjs 분석 보고서

educationexploitationlabs-practice+3
15 months ago
vuln_apps preview

vuln_apps

GitHubclickswave/vuln_apps

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

api-securityeducationlabs-practice+3
121 days ago
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

data-exfiltrationemail-securityexploitation+6
16 days ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
1 month ago
CVE-2017-18349 preview

CVE-2017-18349

GitHubdungsocool/cve-2017-18349

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…

binary-exploitationeducationexploitation+6
3 months ago
CVE-2014-3120 preview

CVE-2014-3120

GitHubdungsocool/cve-2014-3120

Step-by-step lab guide demonstrating CVE-2014-3120 exploitation against Elasticsearch 1.1.1, covering vulnerability analysis, RCE via MVEL scripting,…

container-securityeducationexploitation+3
3 months ago
CVE-2017-11610 preview

CVE-2017-11610

GitHubdungsocool/cve-2017-11610

Step-by-step exploit writeup for CVE-2017-11610 (Supervisord XML-RPC RCE) with attack surface analysis, namespace traversal discovery, and…

educationexploitationlabs-practice+4
3 months ago
cve-2018-15961 preview

cve-2018-15961

GitHubcved-sources/cve-2018-15961

Docker container for CVE-2018-15961, part of the Cved framework for managing and testing vulnerable Docker environments in security labs.

container-securityeducationexploitation+3
15 years ago
CrushFTP-CVE-2024-4040-Proof-of-Concept preview

CrushFTP-CVE-2024-4040-Proof-of-Concept

GitHubsidjaz/crushftp-cve-2024-4040-proof-of-concept

Proof-of-concept exploit for CVE-2024-4040, demonstrating unauthenticated SSTI and local file read in CrushFTP, with Docker lab and mitigation…

educationexploitationlabs-practice+3
3 months ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubpedrorichil/cve-2025-49844

Educational lab environment demonstrating CVE-2025-49844 (RediShell) in Redis. Includes Docker setup, exploit PoC script, and security…

educationexploitationlabs-practice+3
610 months ago
gp_netSecDSS preview

gp_netSecDSS

GitLabahmad.zaid/netsecdss

Decision Support System for Risk Assessing Network and System Security in Small and Medium Enterprises (SMEs), A graduation project.

educationlabs-practicenetwork-security
1 month ago
CVE-2021-23394 preview

CVE-2021-23394

GitHub0xnemian/cve-2021-23394

Docker container to setup a vulnerable elfinder version on both nginx and apache servers. Can be used to test vulnerability POC

container-securityeducationlabs-practice+3
9 months ago
Previous12…53Next