Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
897 results
CVE-2025-49844 preview

CVE-2025-49844

GitHubpedrorichil/cve-2025-49844

Educational lab environment demonstrating CVE-2025-49844 (RediShell) in Redis. Includes Docker setup, exploit PoC script, and security…

educationexploitationlabs-practice+3
6
11 months ago
CVE-2026-44338-Lab preview

CVE-2026-44338-Lab

GitHubrootdirective-sec/cve-2026-44338-lab

Docker-based lab demonstrating CVE-2026-44338 authentication bypass in PraisonAI's legacy Flask API. Includes vulnerable and patched services with…

authenticationeducationlabs-practice+3
4 months ago
drupalgeddon2-cve-lab preview

drupalgeddon2-cve-lab

GitHubvaibhav91one/drupalgeddon2-cve-lab

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

container-securityeducationlabs-practice+3
29 days ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
5 months ago
CVE-2017-9841 preview

CVE-2017-9841

GitHubdream434/cve-2017-9841

Exploit script for CVE-2017-9841 targeting PHP unit test remote code execution. Includes a local test environment via Docker for educational security…

educationexploitationpenetration-testing+2
11 year ago
CVE-2026-27541-Analysis-Lab preview

CVE-2026-27541-Analysis-Lab

GitHubrootdirective-sec/cve-2026-27541-analysis-lab

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

educationexploitationlabs-practice+4
6 months ago
CVE-2026-17532-lab preview

CVE-2026-17532-lab

GitHubkalhoralireza/cve-2026-17532-lab

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

educationexploitationlabs-practice+3
1 month ago
CVE-2026-46645-Analysis-Lab preview

CVE-2026-46645-Analysis-Lab

GitHubrootdirective-sec/cve-2026-46645-analysis-lab

Docker-based lab for reproducing CVE-2026-46645, an authorization bypass in SQLAdmin's ajax_lookup endpoint. Includes vulnerable and patched targets,…

api-security-testingeducationlabs-practice+3
3 months ago
cve-2022-42889-text4shell-docker preview

cve-2022-42889-text4shell-docker

GitHubkarthikuj/cve-2022-42889-text4shell-docker

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

container-securityeducationexploitation+3
763 years ago
cve-2017-5638 preview

cve-2017-5638

GitHubjrrdev/cve-2017-5638

Docker-based vulnerable environment and Python exploit script demonstrating CVE-2017-5638 (Apache Struts2 RCE) for educational security testing.

educationexploitationpenetration-testing+2
149 years ago
CVE-2026-8206-Lab preview

CVE-2026-8206-Lab

GitHubrootdirective-sec/cve-2026-8206-lab

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…

ctfeducationexploitation+3
3 months ago
audit-xss-cve-2020-7934 preview

audit-xss-cve-2020-7934

GitHubgiardinas-dev/audit-xss-cve-2020-7934

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

ctfeducationexploitation+3
4 years ago
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

api-security-testingeducationexploitation+4
1 month ago
CVE-2026-24136-Lab preview

CVE-2026-24136-Lab

GitHubblankbire/cve-2026-24136-lab

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

api-security-testingeducationlabs-practice+3
13 months ago
CVE-2026-79752 preview

CVE-2026-79752

GitHubabraxas/cve-2026-79752

CVE-2026-79752 disclosure pack for CakePHP 5.2.13 SQL injection via FunctionsBuilder::cast, with a Python PoC script and Docker lab for authorized…

database-securityeducationexploitation+6
9 days ago
CVE-2024-53900 preview

CVE-2024-53900

GitHubwww-spam/cve-2024-53900

Reproducible environment and PoC for CVE-2024-53900, a critical RCE in Mongoose via populate().match $where. Includes automated exploit script and…

educationexploitationpayload-development+3
1 year ago
CVE-2025-27407 preview

CVE-2025-27407

GitHublogggg2402/cve-2025-27407

Local lab and proof-of-concept exploit for CVE-2025-27407, targeting GitLab's GraphQL introspection schema loader via the Direct Transfer HTTP path.…

educationexploitationlabs-practice+3
5 months ago
CVE-2025-1094-PoC-Postgre-SQLi preview

CVE-2025-1094-PoC-Postgre-SQLi

GitHubishwardeepp/cve-2025-1094-poc-postgre-sqli

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

code-analysisdatabase-securityeducation+5
61 year ago
Previous12…50Next