Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
CVE-2026-9254 preview

CVE-2026-9254

GitHubslagzz/cve-2026-9254

TP-Link Archer BE800 V1 — Parental Control LAN RCE

exploitationhardware-iot-securityiot-security+3
1 day ago
unleashed-firmware preview

unleashed-firmware

GitHubdarkflippers/unleashed-firmware

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

embedded-systems-securityfuzzinghardware-hacking+7
22.1k3 days ago
CVE-2026-23004-Automotive-UDS-Authentication-Bypass-via-Replay-Attack preview

CVE-2026-23004-Automotive-UDS-Authentication-Bypass-via-Replay-Attack

GitHubgeorge0papasotiriou/cve-2026-23004-automotive-uds-authentication-bypass-via-replay-attack

Proof-of-concept exploit demonstrating UDS authentication bypass via challenge-response replay on automotive ECUs, with Python CAN-UDS simulator.

authentication-authorizationembedded-systems-securityexploitation+4
20 days ago
unknownpwn.github.io preview

unknownpwn.github.io

GitHubunknownpwn-zz/unknownpwn.github.io

Public disclosure of Tecnovision DlxSpot Player 4 vulnerabilities: hardcoded SSH credentials, SQL injection, and arbitrary file upload to remote code…

exploitationhardware-iot-securityiot-security+3
28 years ago
traccar preview

traccar

GitHubtraccar/traccar

Open-source GPS tracking system supporting 200+ protocols and 2000+ device models. Provides real-time tracking, geofencing, driver monitoring, and…

api-securitycloud-securityembedded-systems-security+3
7.7k2 days ago
Netis-N5VN-AC1200-DOS preview

Netis-N5VN-AC1200-DOS

GitHubvanlam2001/netis-n5vn-ac1200-dos

Proof-of-concept exploit for a buffer overflow vulnerability (CVE-2024-44596) in Netis N5VN AC1200 routers, causing a denial of service by crashing…

exploitationfuzzinghardware-iot-security+3
0 years ago
SpaceX-Starlink-Router-Gen-2-XSS preview

SpaceX-Starlink-Router-Gen-2-XSS

GitHubyoshida-git-ai/spacex-starlink-router-gen-2-xss

Proof-of-concept exploit for CVE-2023-49965: Cross-Site Scripting (XSS) in Starlink Router Gen 2 captive portal, enabling CSRF-based control of…

exploitationhardware-iot-securityiot-security+3
12 years ago
XM_ONVIF_auth_bypass preview

XM_ONVIF_auth_bypass

GitHubkostasereksonas/xm_onvif_auth_bypass

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

exploitationhardware-iot-securityiot-security+3
26 months ago
eWeLink-QR-Code preview

eWeLink-QR-Code

GitHubsalgio/ewelink-qr-code

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

cryptographyexploitationhardware-iot-security+3
15 years ago
cve-2025-29384 preview

cve-2025-29384

GitHubfomovet/cve-2025-29384

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

binary-exploitationeducationembedded-systems-security+8
2 months ago
CVE-2024-54887-PoC preview

CVE-2024-54887-PoC

GitHubgumbraise/cve-2024-54887-poc

TypeScript PoC for CVE-2024-54887 (TP-Link TL-WR940N authenticated RCE)

exploitationhardware-iot-securityiot-security+4
2 months ago
-CVE-2024-45352 preview

-CVE-2024-45352

GitHubedwins907/-cve-2024-45352

Technical PoC and analysis of CVE-2024-45352, a critical unauthenticated RCE in Xiaomi Smarthome via improper API input handling, with exploit…

exploitationhardware-iot-securityiot-security+3
11 year ago
CVE-2022-25064 preview

CVE-2022-25064

GitHubmr-xn/cve-2022-25064

Python exploit for TP-Link TL-WR840N RCE (CVE-2022-25064) via crafted IPv6 address payload in the router's CGI interface, enabling remote command…

exploitationhardware-iot-securityiot-security+4
224 years ago
CVE-2019-18370_XiaoMi_Mi_WIFI_RCE_analysis preview

CVE-2019-18370_XiaoMi_Mi_WIFI_RCE_analysis

GitHubfzbacon/cve-2019-18370_xiaomi_mi_wifi_rce_analysis
exploitationhardware-iot-securityiot-security+4
23 years ago
CVE-2025-52688 preview

CVE-2025-52688

GitHubjoelczk/cve-2025-52688

Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…

command-and-controlexploitationhardware-iot-security+3
21 year ago
CVE-2022-25062 preview

CVE-2022-25062

GitHubexploitwritter/cve-2022-25062

This script exploits a vulnerability (IoF) in the TPLink WR840N router, using a field for injecting code in the module DNS.

exploitationhardware-iot-securityiot-security+3
4 years ago
netwave-dosvulnerability preview

netwave-dosvulnerability

GitHubdreadlocked/netwave-dosvulnerability

[CVE-2018-6479] Netwave IP Camera server vulnerable to Denial of Service via one single huge POST request.

exploitationhardware-iot-securityiot-security+2
58 years ago
IoT_vuln preview

IoT_vuln

GitHubc0nyy/iot_vuln

Proof-of-concept exploits for IoT device vulnerabilities, including TOTOLINK login bypass CVEs, with detailed technical analysis and reproduction…

exploitationhardware-iot-securityiot-security+2
1 year ago
Previous12Next