Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21+ results
CVE-2018-9995-DVR-Credentials-Extractor preview

CVE-2018-9995-DVR-Credentials-Extractor

GitHubf7p-h4nn1b4l/cve-2018-9995-dvr-credentials-extractor

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

authenticationembedded-systems-securityexploitation+5
1
24 days ago
tiandy-research preview

tiandy-research

GitHubzb3/tiandy-research

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

authenticationembedded-systems-securityexploitation+7
305 years ago
Galdralag-firmware preview

Galdralag-firmware

GitHubsupermagnum/galdralag-firmware

A attempt at cryptographic framework for Baochip-1x .

authenticationcryptographyembedded-systems-security+4
31 month ago
CVE-2025-45466 preview

CVE-2025-45466

GitHubzgsnj123/cve-2025-45466

Disclosure of CVE-2025-45466 detailing hardcoded plaintext SSH credentials in Unitree Go1 robotic dog firmware, enabling remote code execution,…

authenticationembedded-systems-securityexploitation+6
11 year ago
CVE-2025-65427 preview

CVE-2025-65427

GitHubkirubel-cve/cve-2025-65427

Proof-of-concept exploit for CVE-2025-65427: missing rate limiting on Dbit N300 T1 Pro router login API enabling brute-force attacks and…

authenticationiot-securitypassword-attacks+3
8 months ago
SYNwall preview

SYNwall

GitHubsynwall/synwall

Linux kernel module implementing a zero-configuration, OTP-based firewall for IoT devices. Transparently authenticates network traffic using a…

authenticationembedded-systems-securityiot-security+1
2623 months ago
linux-fingerprint-r503 preview

linux-fingerprint-r503

GitHubmatpb/linux-fingerprint-r503

Linux desktop fingerprint login using a Grow R503 sensor + Arduino + a Rust fprintd-replacement daemon

authenticationcryptographyembedded-systems-security+3
451 month ago
D-Link-CVE-2021-27342-exploit preview

D-Link-CVE-2021-27342-exploit

GitHubmavlevin/d-link-cve-2021-27342-exploit

Exploit for CVE-2021-27342 vulnerability (telnet authentication brute-force protection bypass)

authenticationembedded-systems-securityexploitation+3
155 years ago
CVE-2026-36438 preview

CVE-2026-36438

GitHubkensh1k/cve-2026-36438

Documentation of CVE-2026-36438: a vulnerability in Intelbras VIP 1230 B/D G4 devices allowing remote attackers to obtain administrator account…

authenticationembedded-systems-securityinformation-gathering+3
3 months ago
CVE-2013-6117 preview

CVE-2013-6117

GitHubmilo2012/cve-2013-6117

Exploit tool for CVE-2013-6117, targeting Dahua DVR authentication bypass. Scans IP lists concurrently to extract device credentials via HTTP.

authenticationexploitationiot-security+2
88 years ago
CVE-2025-67158 preview

CVE-2025-67158

GitHubremenis/cve-2025-67158

Revotech I6032W-FHW IP camera firmware fails to validate authentication fields in API requests, allowing attackers to bypass authentication and…

authenticationexploitationiot-security+3
7 months ago
CVE-2025-67159 preview

CVE-2025-67159

GitHubremenis/cve-2025-67159

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

authenticationexploitationhardware-iot-security+3
7 months ago
CVE-2025-45620 preview

CVE-2025-45620

GitHubweedl/cve-2025-45620

Disclosure of client-side authentication bypass in AVer camera web interface exposing unencrypted credentials via network traffic monitoring.

authenticationhardware-securityiot-security+3
1 year ago
shim preview

shim

GitHubrhboot/shim

First-stage UEFI bootloader that enforces Secure Boot by validating signed binaries, installing runtime loader protocols, and measuring loaded…

authenticationcryptographydefensive-tools+3
1.1k29 days ago
ft9201-libfprint preview

ft9201-libfprint

GitHubomgrant/ft9201-libfprint

Linux libfprint driver for the Focal-systems FT9201 (2808:93a9) USB fingerprint reader — runs FocalTech's own Windows matching engine natively on…

authenticationbinary-analysisembedded-systems-security+4
241 month ago
CVE-2025-63667 preview

CVE-2025-63667

GitHubremenis/cve-2025-63667

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

api-securityauthenticationembedded-systems-security+4
19 months ago
dlink preview

dlink

GitHubnetsecfish/dlink

Proof-of-concept exploit and analysis for command injection and hardcoded backdoor credentials in D-Link NAS devices, enabling unauthenticated remote…

authenticationexploitationiot-security+3
1002 years ago
Previous12Next