Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
94 results
CVE-2026-75616 preview

CVE-2026-75616

GitHubtotekuh/cve-2026-75616

Proof-of-concept exploit for authenticated OS command injection in TP-Link Archer C20 v6 web management interface, executing root commands via BPA…

embedded-systems-securityexploitationiot-security+1
2 days ago
CVE-2026-6837-zyxel-export-cgi-command-injection preview

CVE-2026-6837-zyxel-export-cgi-command-injection

GitHubminanagehsalalma/cve-2026-6837-zyxel-export-cgi-command-injection

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

embedded-systems-securityexploitationfirmware-analysis+3
39 days ago
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityexploitationiot-security+5
113 days ago
CVE-2018-9995-DVR-Credentials-Extractor preview

CVE-2018-9995-DVR-Credentials-Extractor

GitHubf7p-h4nn1b4l/cve-2018-9995-dvr-credentials-extractor

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

authenticationembedded-systems-securityexploitation+5
123 days ago
CVE-2022-30024 preview

CVE-2022-30024

GitHubilizavr/cve-2022-30024

Python-based PoC exploit for CVE-2022-30024 enabling remote code execution on TP-Link WR841 v10 routers.

embedded-systems-securityexploitationvulnerability-analysis+1
125 days ago
CVE-2026-8023 preview

CVE-2026-8023

GitHubret2c/cve-2026-8023

Proof-of-concept exploit for pre-authentication path traversal in Zephyr RTOS HTTP server static-fs handler, demonstrating directory traversal via…

embedded-systems-securityexploitationiot-security+3
2 months ago
cve-2025-29384 preview

cve-2025-29384

GitHubfomovet/cve-2025-29384

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

binary-exploitationeducationembedded-systems-security+8
2 months ago
glinet-beryl-ax-triple-rce-cve-2026-11450-11451-11452-unauthenticated-root-on-travel-router preview

glinet-beryl-ax-triple-rce-cve-2026-11450-11451-11452-unauthenticated-root-on-travel-router

GitHubhunt-benito/glinet-beryl-ax-triple-rce-cve-2026-11450-11451-11452-unauthenticated-root-on-travel-router

PoC for three unauthenticated command injection vulnerabilities (CVE-2026-11450/1/2) in GL.iNet Beryl AX travel router firmware <=4.4.5, exploiting…

educationembedded-systems-securityexploitation+3
12 months ago
CVE-2025-63821 preview

CVE-2025-63821

GitHubxernary/cve-2025-63821

Proof-of-concept of vulnerability found in Totolink A720R router

embedded-systems-securityexploitationfirmware-analysis+3
2 months ago
T3-Technology-CPE-Advisories preview

T3-Technology-CPE-Advisories

GitHubpwnonu/t3-technology-cpe-advisories

CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE

embedded-systems-securityexploitationhardware-security+5
2 months ago
ASUS-AiCloud-RCE preview

ASUS-AiCloud-RCE

GitHubmurrez/asus-aicloud-rce

SETROOTCERTIFICATE (write /etc/cert.pem.1) + APPLYAPP (RC_SERVICE execution). Refs: CVE-2025-2492, CVE-2024-12912, CVE-2025-59366; runZero;…

embedded-systems-securityexploitationiot-security+4
3 months ago
Best-Practices-Cybersecurity-Otanata-Project preview

Best-Practices-Cybersecurity-Otanata-Project

GitHubaskhatov21/best-practices-cybersecurity-otanata-project

CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata

command-and-controleducationembedded-systems-security+8
4 months ago
duckLogger preview

duckLogger

GitHubitsmmdoha/ducklogger

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

command-and-controldata-exfiltrationembedded-systems-security+8
874 months ago
CVE-2025-1739 preview

CVE-2025-1739

GitHubn0n4m3x41/cve-2025-1739

Proof-of-concept exploit for CVE-2025-1739 demonstrating authentication bypass via Base64-encoded Basic Auth token leakage on Trivision NC227WF IP…

authentication-authorizationeducationembedded-systems-security+4
4 months ago
CVE-2025-34037 preview

CVE-2025-34037

GitHubtaxanehh/cve-2025-34037

Python port of the Linksys tmUnblock.cgi RCE exploit

command-and-controleducationembedded-systems-security+4
5 months ago
CVE-2020-10558 preview

CVE-2020-10558

GitHubnullze/cve-2020-10558

Documentation of CVE-2020-10558: a remote DoS vulnerability in Tesla Model S/3/X infotainment systems via crafted web pages, with technical analysis,…

educationembedded-systems-securityexploitation+4
156 months ago
CVE-2025-67445 preview

CVE-2025-67445

GitHubdarkspoook/cve-2025-67445

Proof-of-concept exploit for CVE-2025-67445: unauthenticated remote DoS via oversized HTTP POST request causing segmentation fault in TOTOLINK X5000R…

embedded-systems-securityexploitationiot-security+2
6 months ago
exploits preview

exploits

GitHubhackerhouse-opensource/exploits

Collection of proof-of-concept exploits covering local and remote code execution, privilege escalation, web application flaws, and mobile/embedded…

binary-exploitationcurated-resourcesembedded-systems-security+7
4706 months ago
Previous123456Next