Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
cve-2015-1187-dir820l-firmware-reverse-engineering preview

cve-2015-1187-dir820l-firmware-reverse-engineering

GitHubchristopher-leese/cve-2015-1187-dir820l-firmware-reverse-engineering

Static firmware reverse engineering of CVE-2015-1187: unauthenticated command injection in D-Link DIR-820L. MIPS root filesystem extraction with…

embedded-systems-securityexploitationfirmware-analysis+5
1 month ago
DIR-890L-1.20-RCE preview

DIR-890L-1.20-RCE

GitHubtyeyeah/dir-890l-1.20-rce

Analysis and PoC for D-Link DIR-890L RCE (CVE-2022-29778)

command-and-controlembedded-systems-securityexploitation+3
14 years ago
CVE-2026-56111 preview

CVE-2026-56111

GitHubchristbowel/cve-2026-56111

Proof-of-concept exploit for CVE-2026-56111, an out-of-bounds write in the M421 G-code handler of Marlin Firmware, demonstrating constrained memory…

binary-exploitationembedded-systems-securityexploitation+3
13 months ago
asus-cmd preview

asus-cmd

GitHubjduck/asus-cmd

ASUS Router infosvr UDP Broadcast root Command Execution

embedded-systems-securityexploitationhardware-iot-security+4
25211 years ago
Dji_ble_vuln preview

Dji_ble_vuln

GitHubfeedbeef/dji_ble_vuln

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

bluetooth-securitycommand-and-controlembedded-systems-security+6
12 days ago
CVE-2020-8958 preview
Archived

CVE-2020-8958

GitHubqurbat/cve-2020-8958

Proof of concept for arbitrary OS command execution on Guangzhou/V-SOL 1GE ONU devices (CVE-2020-8958)

embedded-systems-securityexploitationhardware-iot-security+3
75 years ago
CVE-2025-15545 preview

CVE-2025-15545

GitHubxernary/cve-2025-15545

Proof of Concept for CVE-2025-15545

command-and-controlembedded-systems-securityexploitation+3
18 months ago
DSL-2750U-Full-chain preview

DSL-2750U-Full-chain

GitHubhadimed/dsl-2750u-full-chain

CVE-2021-3707 , CVE-2021-3708

command-and-controlembedded-systems-securityexploitation+3
214 years ago
CVE-2025-0690 preview

CVE-2025-0690

GitHubkaleth4/cve-2025-0690

Technical analysis of CVE-2025-0690: integer overflow in GRUB2's read command leading to heap out-of-bounds write, arbitrary code execution, and…

binary-exploitationeducationembedded-systems-security+3
5 months ago
IoT-Implant-Toolkit preview

IoT-Implant-Toolkit

GitHubarthastang/iot-implant-toolkit

Toolkit for implant attack of IoT devices

binary-analysisembedded-systems-securityexploitation+8
1358 years ago
CVE-2023-36143 preview

CVE-2023-36143

GitHubrobintrigon/cve-2023-36143

Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.

embedded-systems-securityexploitationiot-security+2
3 years ago
CVE-2023-33381-MitraStar-GPT-2741GNAC preview

CVE-2023-33381-MitraStar-GPT-2741GNAC

GitHubduality084/cve-2023-33381-mitrastar-gpt-2741gnac

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

binary-analysisembedded-systems-securityexploitation+4
133 years ago
CVE-2024-30167 preview

CVE-2024-30167

GitHubrizzziom/cve-2024-30167

Proof-of-concept exploit for authenticated command injection in Atlona AT-OME-RX21, allowing root-level command execution via the time configuration…

command-and-controlembedded-systems-securityexploitation+3
19 months ago
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityexploitationiot-security+5
11 month ago
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

binary-analysiscommand-and-controlembedded-systems-security+7
21 year ago
esp32-cve-2025-27840-power-trace-experiment preview

esp32-cve-2025-27840-power-trace-experiment

GitHubjasonw88/esp32-cve-2025-27840-power-trace-experiment

Firmware for getting a power trace of the behavior of the bluetooth module on the ESP32 when the ESP32 is sent the undocumented hci bluetooth…

bluetooth-securityembedded-systems-securityhardware-hacking+2
2 months ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub234329a423853/cve-2021-4045

CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all…

embedded-systems-securityexploitationfirmware-analysis+3
19 months ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
21 month ago
Previous1234Next