Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
4804 results
mutillidae preview

mutillidae

GitHubwebpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

ctfeducationlabs-practice+3
1.5k9 days ago
Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212- preview

Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212-

GitHubjasalurah/creating-a-vulnerable-docker-environment-cve-2023-30212-

Docker-based vulnerable environment for practicing CVE-2023-30212 exploitation, featuring an OURPHP web app with a reflected XSS vulnerability for…

container-securityeducationexploitation+3
3 years ago
CVE-2026-2964-Lab preview

CVE-2026-2964-Lab

GitHubthegenetic/cve-2026-2964-lab

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

code-analysiseducationexploitation+4
6 months ago
DVWA preview

DVWA

GitHubdigininja/dvwa

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

educationlabs-practicepenetration-testing+2
13.8k3 days ago
CVE-2021-42013 preview

CVE-2021-42013

GitHublayarkacasiber/cve-2021-42013

Docker-based lab environment for exploiting CVE-2021-42013 (Apache HTTP Server path traversal and RCE) with step-by-step setup instructions for…

container-securityeducationexploitation+3
4 years ago
POC-CVE-2026-58048 preview

POC-CVE-2026-58048

GitHubimbas007/poc-cve-2026-58048

Security research project

database-securityexploitationlabs-practice+4
22 months ago
CVE-2024-10924-Wordpress-Docker preview

CVE-2024-10924-Wordpress-Docker

GitHubtrackflaw/cve-2024-10924-wordpress-docker

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

authenticationexploitationlabs-practice+3
31 year ago
cve-2026-87902-poc preview

cve-2026-87902-poc

GitHubressl/cve-2026-87902-poc

PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned…

exploitationlabs-practicepenetration-testing+4
3811 days ago
CVE-2026-89274-wp-recipe-maker-poc preview

CVE-2026-89274-wp-recipe-maker-poc

GitHubhassham1/cve-2026-89274-wp-recipe-maker-poc

Docker validation lab and Python PoC for CVE-2026-89274, proving arbitrary shortcode execution in WP Recipe Maker <= 10.8.1 via rating-comment…

exploitationlabs-practicepenetration-testing+5
10 days ago
CVE-2026-12227-visualcomposer-lfi-poc preview

CVE-2026-12227-visualcomposer-lfi-poc

GitHubhassham1/cve-2026-12227-visualcomposer-lfi-poc

Docker validation lab and safe-oracle PoC for CVE-2026-12227, an unauthenticated LFI in Visual Composer via vcv-template, with a nuclei detection…

exploitationlabs-practicepenetration-testing+5
19 days ago
CVE-2026-94545-nextjs-og-poc preview

CVE-2026-94545-nextjs-og-poc

GitHubhassham1/cve-2026-94545-nextjs-og-poc

Isolated Docker lab and non-destructive Python scanner reproducing CVE-2026-94545, the Next.js next/og ImageResponse SVG injection, with vulnerable…

exploitationlabs-practicevulnerability-analysis+3
110 days ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
Spring4Shell-POC preview

Spring4Shell-POC

GitHublunasec-io/spring4shell-poc

This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).

exploitationlabs-practicepayload-development+4
1064 years ago
Comment2Shell preview

Comment2Shell

GitHubdeathshotxd/comment2shell

Zero-click pre-auth WordPress CVE-2026-93485 exploit chain: stored XSS in wpautop() escalates to admin-session plugin upload and a self-deleting…

exploitationlabs-practicepayload-development+7
613 days ago
wafaray preview

wafaray

GitHubalt3kx/wafaray

Enhance your malware detection with WAF + YARA (WAFARAY)

defensive-toolslabs-practicemalware-analysis+4
1084 years ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubvulpecuna/cve-2026-87902

Python PoC for CVE-2026-87902, an unauthenticated WordPress path traversal RCE via get_page_template(), with version fingerprinting, theme checks,…

exploitationlabs-practicepenetration-testing+5
910 days ago
KindaRails2Shell preview

KindaRails2Shell

GitHub0xsha/kindarails2shell

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

exploitationlabs-practicepayload-development+4
42 months ago
CVE-2026-81294 preview

CVE-2026-81294

GitHubabraxas/cve-2026-81294

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified…

authenticationexploitationlabs-practice+5
314 days ago
Previous12…100Next