Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
not-slithering-anywhere preview

not-slithering-anywhere

GitHubtrailofbits/not-slithering-anywhere

The Python Version of our Not Go-ing Anywhere Vulnerable Application

dynamic-analysis-sandboxingeducationlabs-practice+3
11
2 years ago
PIL-CVE-2017-8291 preview

PIL-CVE-2017-8291

GitHubdaniilorchikov/pil-cve-2017-8291

Educational PoC for CVE-2017-8291 (GhostButt) demonstrating remote command execution via Python PIL/Pillow EPS image processing with GhostScript…

binary-exploitationeducationexploitation+3
9 months ago
CVE-2017-8291 preview

CVE-2017-8291

GitHubshun1403/cve-2017-8291

Docker-based lab demonstrating CVE-2017-8291 (GhostButt) exploitation via Python PIL/Pillow EPS image processing, with a vulnerable web application…

ctfeducationexploitation+3
1 year ago
CVE-2022-44900-demo-lab preview

CVE-2022-44900-demo-lab

GitHub0xless/cve-2022-44900-demo-lab

Demo webapp vulnerable to CVE-2022-44900

educationexploitationlabs-practice+3
18 months ago
S.P.A.R.K--Standard-Python-ASCII-RPG-Kit- preview

S.P.A.R.K--Standard-Python-ASCII-RPG-Kit-

GitHubninedeadeyes/s.p.a.r.k--standard-python-ascii-rpg-kit-

Light Weight 2d Ascii RPG Python Game Engine

educationgeneral-purpose-utilitieslabs-practice+1
31 month ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubvulpecuna/cve-2026-87902

Python PoC for CVE-2026-87902, an unauthenticated WordPress path traversal RCE via get_page_template(), with version fingerprinting, theme checks,…

exploitationlabs-practicepenetration-testing+5
35 days ago
POC-CVE-2023-32681 preview
Archived

POC-CVE-2023-32681

GitHubhardikmodha/poc-cve-2023-32681

POC for the CVE-2023-32681

educationexploitationlabs-practice+2
43 years ago
CVE-2024-4367-hands-on preview

CVE-2024-4367-hands-on

GitHubpenguincabinet/cve-2024-4367-hands-on

Hands-on lab to learn CVE-2024-4367 (Firefox PDF.js RCE) with PoC generation, vulnerable browser launch, and patched version verification.

educationexploitationlabs-practice+2
1 year ago
PoC-2023-43208 preview

PoC-2023-43208

GitHubmkirahmet/poc-2023-43208

A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.

educationexploitationlabs-practice+3
37 months ago
nginx-ui-CVE-2026-42221-CVE-2026-42238- preview

nginx-ui-CVE-2026-42221-CVE-2026-42238-

GitHubfuchiuebusi-lab/nginx-ui-cve-2026-42221-cve-2026-42238-

Docker-based lab environment to verify and exploit two unauthenticated API vulnerabilities (CVE-2026-42221, CVE-2026-42238) in nginx-ui, with patched…

educationexploitationlabs-practice+3
3 months ago
CVE-2025-1974 preview

CVE-2025-1974

GitHubzsxen/cve-2025-1974

Windows 11-first educational lab for studying CVE-2025-1974 in ingress-nginx. Provides safe attack emulation and defense validation with local…

cloud-securitycontainer-securitydefensive-tools+7
5 months ago
ChamiloLMS-CVE-2023-4220 preview

ChamiloLMS-CVE-2023-4220

GitHubspeatx/chamilolms-cve-2023-4220

CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.

ctfeducationexploitation+5
4 months ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

educationexploitationlabs-practice+3
22 years ago
cve-2023-29357-Sharepoint preview

cve-2023-29357-Sharepoint

GitHubguillaume-risch/cve-2023-29357-sharepoint

Proof-of-concept exploit for CVE-2023-29357 targeting SharePoint, with automated Vagrant lab environment for testing and education.

educationexploitationlabs-practice+3
42 years ago
vaas-cve-2015-5477 preview

vaas-cve-2015-5477

GitHubhmlio/vaas-cve-2015-5477

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

container-securitydns-analysiseducation+3
111 years ago
CVE-2019-16784-POC preview

CVE-2019-16784-POC

GitHubckrielle/cve-2019-16784-poc

A Proof of Concept exploit for the PyInstaller CVE-2019-16783

binary-exploitationeducationexploitation+4
2 years ago
ThreatPursuit-VM preview
Archived

ThreatPursuit-VM

GitHubmandiant/threatpursuit-vm

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

curated-resourcesdigital-forensicseducation+8
1.3k3 years ago