Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
CVE-2026-3227-TP-Link-authenticated-RCE preview

CVE-2026-3227-TP-Link-authenticated-RCE

GitHubdo4choo/cve-2026-3227-tp-link-authenticated-rce

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

binary-exploitationeducationexploitation+6
42
2 months ago
routers-exploit preview

routers-exploit

GitHubelbertavares/routers-exploit

Proof-of-concept exploits for TP-Link routers, including remote command execution and authentication bypass vulnerabilities.

educationexploitationfirmware-analysis+4
116 years ago
blackvue-cve-2023 preview

blackvue-cve-2023

GitHubeyjhb/blackvue-cve-2023

BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748

educationembedded-systems-securityexploitation+6
102 years ago
CVE-2023-0861-POC preview

CVE-2023-0861-POC

GitHubseifallahhomrani1/cve-2023-0861-poc

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

educationembedded-systems-securityexploitation+5
63 years ago
CVE-2026-6837-zyxel-export-cgi-command-injection preview

CVE-2026-6837-zyxel-export-cgi-command-injection

GitHubminanagehsalalma/cve-2026-6837-zyxel-export-cgi-command-injection

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

embedded-systems-securityexploitationfirmware-analysis+3
39 days ago
CVE-2019-10915 preview

CVE-2019-10915

GitHubjiansiting/cve-2019-10915

Proof-of-concept exploit for CVE-2019-10915 targeting an authentication bypass in Siemens TIA Administrator, enabling remote command execution via…

authentication-authorizationexploitationfirmware-analysis+3
47 years ago
Tenda-F3-V4 preview

Tenda-F3-V4

GitHub4d000/tenda-f3-v4

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

embedded-systems-securityexploitationfirmware-analysis+4
311 months ago
d_link_880_bug preview

d_link_880_bug

GitHubbadnack/d_link_880_bug

Static analysis of D-Link router firmware revealing buffer overflow vulnerabilities in HTTP handling, including CVE-2017-14948, with disassembly and…

binary-analysisembedded-systems-securityexploitation+4
36 years ago
CVE-2025-63821 preview

CVE-2025-63821

GitHubxernary/cve-2025-63821

Proof-of-concept of vulnerability found in Totolink A720R router

embedded-systems-securityexploitationfirmware-analysis+3
2 months ago
CVE-2021-26258 preview

CVE-2021-26258

GitHubzwclose/cve-2021-26258

PoC exploit and tooling for CVE-2021-26258, including a custom storage file packer/unpacker and a MITM web server to deliver malicious updates to…

exploitationfirmware-analysismalware-analysis+3
33 years ago
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

binary-analysiscommand-and-controlembedded-systems-security+7
21 year ago
Fastgate preview

Fastgate

GitHubgaris/fastgate

Detailed analysis of CVE-2019-12489 command injection in Fastgate modem/router firmware, including firmware extraction, reverse engineering with…

command-and-controlembedded-systems-securityexploitation+6
26 years ago
blogpost_cve-2018-19987-analysis preview

blogpost_cve-2018-19987-analysis

GitHubnahueldsanchez/blogpost_cve-2018-19987-analysis

This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers

educationexploitationfirmware-analysis+4
25 years ago
CVE-2024-55211 preview

CVE-2024-55211

GitHubmicaelmaciel/cve-2024-55211

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

authentication-authorizationdns-analysisexploitation+3
210 months ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub234329a423853/cve-2021-4045

Proof-of-concept and analysis for CVE-2021-4045, a command injection RCE in the TP-Link Tapo C200 IP camera's uhttpd affecting firmware prior to…

embedded-systems-securityexploitationfirmware-analysis+3
8 months ago
CVE-2020-12124 preview

CVE-2020-12124

GitHubscorpion-security-labs/cve-2020-12124

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

binary-analysiscommand-and-controleducation+8
6 months ago
CVE-2021-3166 preview

CVE-2021-3166

GitHubkaisersource/cve-2021-3166

Proof-of-concept exploit for CVE-2021-3166 targeting ASUS DSL-N14U routers via malicious firmware upload, triggering a denial-of-service condition.

exploitationfirmware-analysisiot-security+2
3 years ago