Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1556 results
vulnerable-bsr-lab-CVE-2023-6933 preview

vulnerable-bsr-lab-CVE-2023-6933

GitHubtrex96/vulnerable-bsr-lab-cve-2023-6933

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

educationexploit-frameworkslabs-practice+3
11 months ago
sk-cve-2026-26030-lab preview

sk-cve-2026-26030-lab

GitHubinertfluid/sk-cve-2026-26030-lab

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

ai-securitybinary-exploitationeducation+5
12 months ago
gtfocli preview

gtfocli

GitHubcmd-tools/gtfocli

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

ctfinformation-gatheringpenetration-testing+1
191 year ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
8 months ago
pythia-sql-clairvoyance preview

pythia-sql-clairvoyance

GitHubrodhnin/pythia-sql-clairvoyance

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlerdevsecops+5
24 months ago
CVE-2025-9074-PoC preview

CVE-2025-9074-PoC

GitHubbridgeralderson/cve-2025-9074-poc

A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on…

container-escapeexploitationpenetration-testing+3
508 months ago
CVE-2022-25365 preview

CVE-2022-25365

GitHubfollowboy1999/cve-2022-25365

Proof-of-concept exploit for CVE-2022-25365, a privilege escalation vulnerability in Docker Desktop for Windows via named pipe impersonation.

container-escapeexploitationpenetration-testing+3
13 years ago
cve-2025-55182 preview

cve-2025-55182

GitHubps-interactive/cve-2025-55182

Vulnerable REACT app in docker container and poc code - for demos

container-securityeducationexploitation+4
8 months ago
Trickster-HTB preview

Trickster-HTB

GitHubpallangyo98/trickster-htb

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

ctfeducationexploitation+5
1 year ago
CVE-2025-9074-Docker-Desktop-Container-Escape preview

CVE-2025-9074-Docker-Desktop-Container-Escape

GitHubptechamanja/cve-2025-9074-docker-desktop-container-escape

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…

cloud-securitycontainer-escapecontainer-security+4
28 months ago
heartbleed-proof-of-concept preview

heartbleed-proof-of-concept

GitHubundacmic/heartbleed-proof-of-concept

Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. :old_key: :unlock:

educationexploitationpapers-research+2
53 years ago
CVE-2025-9074-Poc preview

CVE-2025-9074-Poc

GitHubzaydbf/cve-2025-9074-poc

Bash-based PoC exploit for CVE-2025-9074 targeting unauthenticated Docker Engine API to achieve container escape and remote code execution via…

container-escapeexploitationpenetration-testing+3
8 months ago
CVE-2025-60787 preview

CVE-2025-60787

GitHubprabhatverma47/cve-2025-60787

Proof-of-concept for CVE-2025-60787, demonstrating remote code execution in MotionEye <= 0.43.1b4 via client-side validation bypass and command…

code-analysisexploitationpenetration-testing+3
11 months ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubc0gnit00/cve-2025-9074

PHP poc, exploit for CVE-2025-9074

cloud-securitycommand-and-controlcontainer-escape+8
3 months ago
motionEye-RCE-through-config-parameter preview

motionEye-RCE-through-config-parameter

GitHubprabhatverma47/motioneye-rce-through-config-parameter

PoC steps for this vulnerability

exploitationpenetration-testingred-teaming+3
211 months ago
cve-2019-5736-exp preview

cve-2019-5736-exp

GitHubmilloni/cve-2019-5736-exp

Exploit for the CVE-2019-5736 runc vulnerability

container-escapeeducationexploitation+2
17 years ago
CVE-2025-29927-Nextjs-Analysis preview

CVE-2025-29927-Nextjs-Analysis

GitHubsangrok-jeon/cve-2025-29927-nextjs-analysis

CVE-2025-29927-Nextjs 분석 보고서

educationexploitationlabs-practice+3
15 months ago
vuln_apps preview

vuln_apps

GitHubclickswave/vuln_apps

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

api-securityeducationlabs-practice+3
121 days ago
Previous12…87Next