Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
167 results
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

binary-analysiscommand-and-controlembedded-systems-security+7
2
1 year ago
CVE-2019-17147 preview

CVE-2019-17147

GitHubimnot-ye/cve-2019-17147

Comprehensive reverse engineering and exploitation of CVE-2019-17147, a stack buffer overflow in TP-Link TL-WR841N routers. Includes firmware…

binary-exploitationeducationembedded-systems-security+9
47 months ago
dcsgonefwbsp preview

dcsgonefwbsp

GitLabcryptoadvocate/dcsgonefwbsp

The firmware board support package home of the Circuit Crafters first electronic badge project.

cryptographyembedded-systems-securityfirmware-analysis+1
24 months ago
CVE-2025-63821 preview

CVE-2025-63821

GitHubxernary/cve-2025-63821

Proof-of-concept of vulnerability found in Totolink A720R router

embedded-systems-securityexploitationfirmware-analysis+3
2 months ago
cve-2015-1187-dir820l-firmware-reverse-engineering preview

cve-2015-1187-dir820l-firmware-reverse-engineering

GitHubchristopher-leese/cve-2015-1187-dir820l-firmware-reverse-engineering

Static firmware reverse engineering of CVE-2015-1187: unauthenticated command injection in D-Link DIR-820L. MIPS root filesystem extraction with…

embedded-systems-securityexploitationfirmware-analysis+5
5 days ago
bd-alaris-firmware-analysis preview

bd-alaris-firmware-analysis

GitHubnadafarafat/bd-alaris-firmware-analysis

Firmware security analysis of BD Alaris 8015 infusion pump (CVE-2016-9355). Identified 6 compound vulnerabilities including plaintext Wi-Fi…

cryptographyeducationembedded-systems-security+5
2 months ago
CVE-2024-31719----AMI-Aptio-5-Vulnerability preview

CVE-2024-31719----AMI-Aptio-5-Vulnerability

GitHubvoltaireyoung/cve-2024-31719----ami-aptio-5-vulnerability

Demonstrates a local access control bypass in AMI Aptio 5 NvLock module, allowing modification of NVRAM variables including administrator password,…

embedded-systems-securityexploitationfirmware-analysis+3
31 year ago
cve-2026-34473-unauthenticated-dos-zte-routers preview

cve-2026-34473-unauthenticated-dos-zte-routers

GitHubminanagehsalalma/cve-2026-34473-unauthenticated-dos-zte-routers

Technical breakdown of CVE-2026-34473, an unauthenticated denial of service affecting 17+ ZTE router models.

embedded-systems-securityexploitationfirmware-analysis+2
23 months ago
iCSeeU preview

iCSeeU

GitHublr-m/icseeu

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

binary-exploitationctfdebuggers+9
21 year ago
fusee-gelee preview

fusee-gelee

GitHuboliviaholly/fusee-gelee

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.

binary-exploitationembedded-systems-securityexploitation+5
5 months ago
CVE-2025-0690 preview

CVE-2025-0690

GitHubkaleth4/cve-2025-0690

Technical analysis of CVE-2025-0690: integer overflow in GRUB2's read command leading to heap out-of-bounds write, arbitrary code execution, and…

binary-exploitationeducationembedded-systems-security+3
4 months ago
cve-2023-31346-poc preview

cve-2023-31346-poc

GitHubfreax13/cve-2023-31346-poc

Proof-of-concept demonstrating memory leaks in AMD SEV-SNP firmware guest message headers and CPUID request, enabling extraction of sensitive guest…

binary-exploitationexploitationfirmware-analysis+3
13 years ago
CVE-2025-51643 preview

CVE-2025-51643

GitHubnastycrow/cve-2025-51643

Documentation of CVE-2025-51643: physical SPI flash extraction on Meitrack T366G-L GPS tracker enabling firmware dump, plaintext credential…

data-exfiltrationembedded-systems-securityexploitation+6
11 year ago
CVE-2025-67399 preview

CVE-2025-67399

GitHubrupeshsurve04/cve-2025-67399

Documentation of CVE-2025-67399: physical UART debug interface exploitation on AIRTH Smart Home AQI Monitor (BK7231N SoC) enabling unauthorized…

embedded-systems-securityexploitationfirmware-analysis+4
7 months ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub234329a423853/cve-2021-4045

CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all…

embedded-systems-securityexploitationfirmware-analysis+3
18 months ago
CVE-2024-33676 preview

CVE-2024-33676

GitHubdersecure/cve-2024-33676

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

authentication-authorizationeducationembedded-systems-security+9
1 year ago
CVE-2022-20607 preview

CVE-2022-20607

GitHubsumeetit/cve-2022-20607

In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with…

android-securityembedded-systems-securityexploitation+3
3 years ago
routerfirmwares preview

routerfirmwares

Bitbucketdudux/routerfirmwares

A bunch of routers firmware images. Principally those that are not available and they do need to be extracted via JTAG, UART, desoldering flash or…

curated-resourcesembedded-systems-securityfirmware-analysis+2
11 years ago
Previous1…456…10Next