Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1011 results
vuln_spring_log4j2 preview

vuln_spring_log4j2

GitHubrecanavar/vuln_spring_log4j2

Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228

educationexploitationlabs-practice+3
4 years ago
docker-log4shell preview

docker-log4shell

GitHuburholaukkarinen/docker-log4shell

Dockerized Go app for testing the CVE-2021-44228 vulnerability

educationexploitationlabs-practice+3
4 years ago
CVE-2022-23305_POC preview

CVE-2022-23305_POC

GitHubtkomlodi/cve-2022-23305_poc

CVE-2022-23305 Log4J JDBCAppender SQl injection POC

database-securityeducationexploitation+3
13 years ago
CVE-2025-68613-n8n-lab preview

CVE-2025-68613-n8n-lab

GitHubr4j3sh-com/cve-2025-68613-n8n-lab

Analysis of CVE-2025-68613

educationexploitationlabs-practice+2
8 months ago
next-js-auth-bypass preview

next-js-auth-bypass

GitHubkazuya256/next-js-auth-bypass

🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For…

authentication-authorizationeducationlabs-practice+3
11 year ago
ninjasworkout preview

ninjasworkout

GitHubeffortlessdevsec/ninjasworkout

Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

educationlabs-practicepenetration-testing+2
972 years ago
kubernetes-goat preview

kubernetes-goat

GitHubmadhuakula/kubernetes-goat

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

cloud-securitycontainer-securityeducation+3
5.8k4 months ago
CVE-2026-44578 preview

CVE-2026-44578

GitHubdinosn/cve-2026-44578

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

cloud-securityeducationexploitation+3
93 months ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

ai-securitycloud-securityeducation+5
228 days ago
CVE-2023-27163 preview

CVE-2023-27163

GitHubdavuxvi/cve-2023-27163

PoC CVE-2023-27163, SSRF, request-baskets hasta v1.2.1

exploitationlabs-practicepenetration-testing+3
13 years ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubzenzue/cve-2025-9074
cloud-securitycontainer-escapecontainer-security+6
100 years ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection
api-securityauthentication-authorizationcryptography+4
21 days ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
viewstate-security-workshop preview

viewstate-security-workshop

GitHubirsdl/viewstate-security-workshop

This repository is for the Testing ASP.NET ViewState with YSoNet (YSoSerial.NET) workshop.

educationexploitationlabs-practice+5
258 months ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubzeyad-azima/cve-2022-1388

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

exploitationlabs-practicepenetration-testing+3
133 years ago
CVE-2024-3116_RCE_in_pgadmin_8.4 preview

CVE-2024-3116_RCE_in_pgadmin_8.4

GitHubtechieneurons/cve-2024-3116_rce_in_pgadmin_8.4

Making a lab and testing the CVE-2024-3116, a Remote Code Execution in pgadmin <=8.4

exploitationlabs-practicepayload-development+3
132 years ago
text4shell-poc preview

text4shell-poc

GitHubsecurekomodo/text4shell-poc

Proof of Concept Appliction for testing CVE-2022-42889

educationexploitationlabs-practice+3
83 years ago
CVE-2026-52199 preview

CVE-2026-52199

GitHublamaper/cve-2026-52199

Proof-of-concept exploit for CVE-2026-52199: unauthenticated remote code execution via exposed ADB daemon on UZ801 4G LTE router. Includes…

educationexploitationlabs-practice+5
1 month ago
Previous12…57Next