Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1865 results
svja preview

svja

GitHubtheronielanddaronpodcastshow/svja

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

api-security-testingauthentication-authorizationeducation+5
13
8 months ago
CVE-2018-14667_Lab_POC preview

CVE-2018-14667_Lab_POC

GitHubaitlmalem/cve-2018-14667_lab_poc

Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

educationexploitationpenetration-testing+2
13 days ago
CVE-2018-14667_Lab_POC preview

CVE-2018-14667_Lab_POC

GitHubr4ch1d0/cve-2018-14667_lab_poc

Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

educationexploitationlabs-practice+2
13 days ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubianxtianxt/cve-2019-19781

Shell-based remote code execution exploit targeting CVE-2019-19781 in Citrix Application Delivery Controller and Citrix Gateway. Executes arbitrary…

command-and-controlexploitationpenetration-testing+3
76 years ago
OpenSource-ERP-SQL-Injection preview

OpenSource-ERP-SQL-Injection

GitHubemreovunc/opensource-erp-sql-injection

CVE-2019-5893 | OpenSource ERP application has SQL Injection vulnerability.

database-securityexploitationpenetration-testing+2
57 years ago
CVE-2022-42889-POC preview

CVE-2022-42889-POC

GitHubakshayithape-devops/cve-2022-42889-poc

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

educationexploitationlabs-practice+3
53 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubderziad/cve-2022-30190

This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability…

educationexploitationpayload-generation+2
61 year ago
Exploits_CVE-2019-19781 preview

Exploits_CVE-2019-19781

GitHubunknowndevice64/exploits_cve-2019-19781

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781). Executes arbitrary commands on vulnerable…

exploitationpenetration-testingred-teaming+3
46 years ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubmariomamo/cve-2022-22965

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) with a vulnerable Spring Boot application, Python exploit script, and Docker-based lab…

educationexploitationpayload-generation+3
54 years ago
CVE-2026-22557-Path-Traversal-Ubiquti-UniFi preview

CVE-2026-22557-Path-Traversal-Ubiquti-UniFi

GitHubgagaltotal/cve-2026-22557-path-traversal-ubiquti-unifi

CVE-2026-22557 Path Traversal Ubiquti UniFi Network Application

educationexploitationinformation-gathering+3
2 months ago
django-cve-2025-64459 preview

django-cve-2025-64459

GitHubjoshualent/django-cve-2025-64459

demo application showing off SQL Injection exploit in django 5.2.7

database-securityeducationpenetration-testing+2
2 months ago
CVE-2023-50164-PoC preview

CVE-2023-50164-PoC

GitHubnikitapark/cve-2023-50164-poc

CVE-2023-50164 PoC Application & Exploit script

educationexploitationpayload-generation+3
11 month ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubsyrins/cve-2025-55182-react2shell-rce

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

command-and-controleducationexploitation+4
39 months ago
CVE-2023-32692-CodeIgniter4 preview

CVE-2023-32692-CodeIgniter4

GitHubmogwailabs/cve-2023-32692-codeigniter4

Example application, vulnerable to CVE-2023-32692 (Validation Rule Injection in the PHP Framework CodeIgniter)

code-analysiseducationlabs-practice+3
23 months ago
cybersecurity-struts2 preview

cybersecurity-struts2

GitHubsighup1/cybersecurity-struts2

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

educationexploitationpayload-development+3
17 years ago
log4shellpoc preview

log4shellpoc

GitHubguerzon/log4shellpoc

Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)

educationexploitationpenetration-testing+2
14 years ago
Vulnerable-Lab-NextJS-CVE-2025-29927 preview

Vulnerable-Lab-NextJS-CVE-2025-29927

GitHubkamal-418/vulnerable-lab-nextjs-cve-2025-29927

Deliberately vulnerable Next.js application designed for practicing exploitation of CVE-2025-29927, with a tutorial video for guided learning.

ctfeducationlabs-practice+2
14 months ago
cacti-rce-cve-2022-46169-vulnerable-application preview

cacti-rce-cve-2022-46169-vulnerable-application

GitHubm3ssap0/cacti-rce-cve-2022-46169-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!

command-and-controlexploitationlabs-practice+3
13 years ago
Previous1…969798…100Next