Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
672 results
log4shell-cve-lab preview

log4shell-cve-lab

GitHubvaibhav91one/log4shell-cve-lab

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

educationexploitationlabs-practice+2
8h 51m ago
shellshock-cve-lab preview

shellshock-cve-lab

GitHubvaibhav91one/shellshock-cve-lab

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

educationexploitationlabs-practice+2
8h 51m ago
CVE-2026-12243-NLTK-PoC preview

CVE-2026-12243-NLTK-PoC

GitHubmorzelowski/cve-2026-12243-nltk-poc

Docker lab demonstrating CVE-2026-12243 path traversal in NLTK before 3.10.0, contrasting vulnerable and patched behavior with a synthetic secret in…

container-securityeducationlabs-practice+2
1 day ago
Project-CVE-2025-54068 preview

Project-CVE-2025-54068

GitHube4zyy/project-cve-2025-54068

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

information-gatheringreconnaissancevulnerability-analysis+2
33 days ago
htb-labs-nexus preview

htb-labs-nexus

GitHubdiegorivas1/htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

ctfeducationexploitation+7
3 days ago
CVE-2026-48060 preview

CVE-2026-48060

GitHubblinky-keys/cve-2026-48060

Proof-of-concept exploit and vulnerable application demonstrating an HTML injection vulnerability in Litestar 2.21.0 via CSRF token, with Docker…

exploitationpenetration-testingvulnerability-analysis+2
5 days ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
405 days ago
WebGoat preview

WebGoat

GitHubwebgoat/webgoat

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

ctfeducationlabs-practice+4
9.3k6 days ago
CVE-2026-18963_analyst preview

CVE-2026-18963_analyst

GitHubminh3102011/cve-2026-18963_analyst

Docker-based lab for reproducing Keycloak CVE-2026-18963, including vulnerable version setup, realm seeding, and source-level workflow analysis with…

authenticationeducationexploitation+3
6 days ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
36 days ago
CVE-2026-10053-lab preview

CVE-2026-10053-lab

GitHubdinosn/cve-2026-10053-lab

Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2,…

educationexploitationlabs-practice+3
47 days ago
retire.js preview

retire.js

GitHubretirejs/retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

static-analysisvulnerability-scannersweb-security
4.2k7 days ago
fix-react2shell-next preview

fix-react2shell-next

GitHubsaied25/fix-react2shell-next

🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.

educationexploitationgeneral-purpose-utilities+2
7 days ago
CVE-2026-76565 preview

CVE-2026-76565

GitHubtoanln-cov/cve-2026-76565

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

exploitationpapers-researchvulnerability-analysis+2
9 days ago
rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android preview

rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android

GitHubhunt-benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android

Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…

android-securitybinary-analysisdefensive-tools+3
19 days ago
CVE-2026-19598 preview

CVE-2026-19598

GitHubsag-asab/cve-2026-19598

Custom Content Types and Fields plugin for WordPress

authentication-authorizationexploitationvulnerability-analysis+2
19 days ago
CVE-2026-8452-check preview

CVE-2026-8452-check

GitHubbishopfox/cve-2026-8452-check

Behavioral patch-state detector for Citrix NetScaler CVE-2026-8452. Sends crafted SAML requests to determine whether the PrefixList size check is…

network-securityvulnerability-analysisvulnerability-scanners+1
110 days ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
310 days ago
Previous12…38Next