Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
SecGen preview

SecGen

GitHubcliffe/secgen

Create randomly insecure VMs

ctfeducationlabs-practice+3
2.8k21h 8m ago
edk2 preview

edk2

GitHubtianocore/edk2

EDK II

cryptographyeducationembedded-systems-security+3
6.3k7 days ago
CVE-2026-34990-poc preview

CVE-2026-34990-poc

GitHubbara-almustafa/cve-2026-34990-poc

CVE-2026-34990 — CUPS <= 2.4.16 Local Privilege Escalation

defensive-toolseducationexploitation+4
8 days ago
CVE-2021-41773-Apache-Path-Traversal-Lab preview

CVE-2021-41773-Apache-Path-Traversal-Lab

GitHub1833ravikumar-max/cve-2021-41773-apache-path-traversal-lab

Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

ctfeducationexploitation+6
8 days ago
CVE-2026-61500 preview

CVE-2026-61500

GitHubaramosf/cve-2026-61500

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

cryptographyeducationexploitation+7
9 days ago
webvm preview

webvm

GitHubleaningtech/webvm

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

cloud-securityctfdevsecops+3
17.4k14 days ago
vulhub preview

vulhub

GitHubvulhub/vulhub

Pre-Built Vulnerable Environments Based on Docker-Compose

educationlabs-practicepenetration-testing+2
21.3k17 days ago
cve-2026-59827-metabase-cyber-range preview

cve-2026-59827-metabase-cyber-range

GitHubshivammittal2403/cve-2026-59827-metabase-cyber-range

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking…

ctfdynamic-analysis-sandboxingeducation+6
18 days ago
GoCD_PoC_Supply_Chain_Attack preview

GoCD_PoC_Supply_Chain_Attack

GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

educationexploitationpayload-generation+7
219 days ago
CVE-2025-64512_PoC preview

CVE-2025-64512_PoC

GitHubjinook-kim/cve-2025-64512_poc

Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

ctfeducationexploitation+5
21 days ago
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

code-analysisdevsecopseducation+4
21 days ago
JFrog_CVE-2026-65615-ByGLM preview

JFrog_CVE-2026-65615-ByGLM

GitHubbl0odz/jfrog_cve-2026-65615-byglm

JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)

educationexploitationlabs-practice+7
22 days ago
CVE-2013-2028-Exploit preview

CVE-2013-2028-Exploit

GitHubvanivamshi/cve-2013-2028-exploit

Docker-based lab and Python exploit for CVE-2013-2028, an Nginx 1.3.9 chunked-parser integer overflow, covering canary recovery, mprotect, and…

binary-exploitationeducationexploitation+6
22 days ago
cve-2026-22732-poc preview

cve-2026-22732-poc

GitHubdylan-chainguard/cve-2026-22732-poc

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

defensive-toolseducationexploitation+3
24 days ago
mirth-connect-security-poc preview

mirth-connect-security-poc

GitHubabhinavagarwal07/mirth-connect-security-poc

Working PoCs for three NextGen Connect 4.5.2 vulnerabilities.

defensive-toolseducationexploitation+4
25 days ago
CVE-2026-53519 preview

CVE-2026-53519

GitHubivanesk315/cve-2026-53519

Docker lab reproducing CVE-2026-53519, a pre-auth path traversal in Nezha Dashboard that leaks jwt_secret_key and enables JWT forgery and admin…

authenticationeducationexploitation+5
25 days ago
CVE-2026-53365 preview

CVE-2026-53365

GitHubhorkimhab/cve-2026-53365

CVE-2026-53365

binary-exploitationcontainer-escapeeducation+4
1 month ago
tandasat.github.io preview

tandasat.github.io

GitHubtandasat/tandasat.github.io

Remote hypervisor development class for security researchers; covers virtualization internals, hypervisor security, and vulnerabilities in privileged…

educationlearning-paths-coursesreverse-engineering+2
194 months ago
Previous12Next