Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1865 results
wordpress-jetpack-broken-access-control-vulnerable-application preview

wordpress-jetpack-broken-access-control-vulnerable-application

GitHubm3ssap0/wordpress-jetpack-broken-access-control-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Jetpack < 13.9.1 broken access control (CVE-2024-9926). Run it at your own risk!

educationexploitationlabs-practice+3
2
1 year ago
CVE-2025-66024 preview

CVE-2025-66024

GitHublukasz-rybak/cve-2025-66024

Proof-of-concept for CVE-2025-66024: Stored XSS in XWiki Blog Application via unescaped post title in HTML title tag. Includes reproduction steps,…

educationpapers-researchvulnerability-analysis+2
5 months ago
EXPLOIT-CVE-2021-44228 preview

EXPLOIT-CVE-2021-44228

GitHubjoaovicdev/exploit-cve-2021-44228

Docker-based educational lab demonstrating Log4Shell (CVE-2021-44228) RCE exploitation with a vulnerable Java application, LDAP redirector, and…

educationexploitationlabs-practice+3
5 months ago
leaflet-cve-2025-69993 preview

leaflet-cve-2025-69993

GitHubpierfrancescoconti/leaflet-cve-2025-69993

Proof-of-concept for CVE-2025-69993: Cross-Site Scripting in Leaflet's bindPopup() method. Includes advisory, impact analysis, and a demo Angular…

educationlabs-practicevulnerability-analysis+2
5 months ago
-CVE-2025-59528-PoC preview

-CVE-2025-59528-PoC

GitHubmaradonam18/-cve-2025-59528-poc

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

ctfeducationexploitation+3
15 months ago
CVE-2026-23744-RCE preview

CVE-2026-23744-RCE

GitHubalisster00/cve-2026-23744-rce

This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object.…

educationexploitationpenetration-testing+3
13 months ago
CVE-2025-55182-test preview

CVE-2025-55182-test

GitHuby3b3l4y3/cve-2025-55182-test

Proof-of-concept demonstrating React2shell vulnerability (CVE-2025-66478) in a Next.js application, providing a base for reproduction and…

educationexploitationpapers-research+2
14 months ago
cve-2025-54988-VulnTikaProject preview

cve-2025-54988-VulnTikaProject

GitHubgaloryber/cve-2025-54988-vulntikaproject

Deliberately vulnerable Spring Boot application using Apache Tika 3.2.1 for testing CVE-2025-54988 XXE exploitation via malicious PDF uploads.

educationexploitationlabs-practice+3
8 months ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubbhanunamikaze/cve-2024-42009

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

data-exfiltrationeducationexploitation+5
11 year ago
CVE-2018-1000529 preview

CVE-2018-1000529

GitHubmartinfrancois/cve-2018-1000529

Proof-of-concept for CVE-2018-1000529: stored XSS in Grails Fields plugin <=2.2.7. Demonstrates the vulnerability with a runnable Grails application…

ctfeducationvulnerability-analysis+2
8 years ago
React2Shell preview

React2Shell

GitHubsubzer0x0/react2shell

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.

container-securityeducationlabs-practice+3
19 months ago
CVE-2021-44228_dockernize preview

CVE-2021-44228_dockernize

GitHubqw3rtyou/cve-2021-44228_dockernize

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

educationexploitationlabs-practice+3
11 year ago
CVE-2025-61148 preview

CVE-2025-61148

GitHubsharma19d/cve-2025-61148

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

api-security-testingeducationinformation-gathering+3
9 months ago
Drupal-Exploit-Lab preview

Drupal-Exploit-Lab

GitHubtea-celikik/drupal-exploit-lab

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

educationexploit-frameworkslabs-practice+3
7 months ago
CVE-2025-56515 preview

CVE-2025-56515

GitHubkov404/cve-2025-56515

Cross-Site Scripting (XSS) Vulnerability in Fiora Chat Application

code-analysisexploitationpenetration-testing+3
11 months ago
Honeypot_Smart_Infrastructure preview

Honeypot_Smart_Infrastructure

GitHubadarkst/honeypot_smart_infrastructure

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

cloud-securitycontainer-securityeducation+4
12 years ago
CVE-2025-34159 preview

CVE-2025-34159

GitHubeyodav/cve-2025-34159

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

cloud-securitycontainer-securityexploitation+5
1 year ago
CVE-2021-44228-poc preview

CVE-2021-44228-poc

GitHubkadantte/cve-2021-44228-poc

log4shell sample application (CVE-2021-44228)

educationexploitationlabs-practice+3
4 years ago
Previous1…979899100Next