Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
CVE-2026-94095 preview

CVE-2026-94095

GitHubhackspeak/cve-2026-94095

PoC for CVE-2026-94095, a traceroute command injection in Netcore NBR200V2 firmware via ubus JSON-RPC, enabling root RCE for authorized testing.

embedded-systems-securityexploitationhardware-iot-security+5
1
14 days ago
CVE-2026-93958 preview

CVE-2026-93958

GitHubhackspeak/cve-2026-93958

Authenticated command injection PoC for D-Link R95/BE9500 DHMAPI SetTimeSettings, achieving root RCE via NTPServer backtick injection, with full…

command-and-controlembedded-systems-securityexploitation+7
415 days ago
CVE-2026-82539 preview

CVE-2026-82539

GitHubxernary/cve-2026-82539

Security advisory for TOTOLINK a720r buffer overflow vulnerability

binary-exploitationembedded-systems-securityexploitation+5
422 days ago
CVE-2026-15469 preview

CVE-2026-15469

GitHubtony102741/cve-2026-15469

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

authenticationcryptographyexploitation+5
21 month ago
CVE-2025-70962 preview

CVE-2025-70962

GitHubnamaek2/cve-2025-70962

CVE-2025-70962 PoC

exploitationfirmware-analysishardware-iot-security+3
2 months ago
CVE-2026-22017-Firmware-Update-via-BLE-Without-Authentication preview

CVE-2026-22017-Firmware-Update-via-BLE-Without-Authentication

GitHubgeorge0papasotiriou/cve-2026-22017-firmware-update-via-ble-without-authentication

Simulated BLE peripheral exposing an unauthenticated GATT firmware-update characteristic; demonstrates critical CVE-2026-22017 device-takeover…

bluetooth-securityembedded-systems-securityexploitation+4
2 months ago
security_articles preview

security_articles

GitHubluismirandaacebedo/security_articles

Technical articles detailing IoT vulnerability research, including WiFi communication flaws and firmware update weaknesses in connected devices, with…

educationembedded-systems-securityhardware-iot-security+3
1112 months ago
CVE-2026-20169 preview

CVE-2026-20169

GitHubgigachadusers/cve-2026-20169

Windows-native IoT vulnerability scanner that discovers exposed management interfaces, tests default credentials, and validates network segmentation…

embedded-systems-securityhardware-iot-securityiot-security+3
12 months ago
buds-audit preview

buds-audit

GitHubspiritualmachines/buds-audit

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

bluetooth-securityembedded-systems-securityexploitation+8
12 months ago
CVE-2026-29115 preview

CVE-2026-29115

GitHubcrimsonfiedofficial/cve-2026-29115

Dahua CVE-2026-29115

embedded-systems-securityexploitationhardware-iot-security+2
12 months ago
CVE-2026-29116 preview

CVE-2026-29116

GitHubcrimsonfiedofficial/cve-2026-29116

Dahua CVE-2026-29116

exploitationhardware-iot-securityiot-security+2
12 months ago
cve-2025-29384 preview

cve-2025-29384

GitHubfomovet/cve-2025-29384

POC for CVE-2025-29384

binary-exploitationeducationembedded-systems-security+8
3 months ago
CVE-2025-1242 preview

CVE-2025-1242

GitHubmichaeladamgroberman/cve-2025-1242

CVE-2025-1242: Hardcoded iothubowner Connection String — Gardyn Home Kit (ICSA-26-055-03)

authenticationcloud-securityfirmware-analysis+4
4 months ago
CVE-2023-26083 preview

CVE-2023-26083

GitHubnoverisp3/cve-2023-26083

CVE-2023-26083-Mali-InfoLeak-PoC

binary-exploitationeducationexploitation+3
4 months ago
CVE-2026-38427 preview

CVE-2026-38427

GitHubsermikr0/cve-2026-38427

CVE-2026-38427 — Integer Wraparound → Heap Buffer Overflow in Tasmota fetch_jpg() uint16_t (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+4
4 months ago
CVE-2026-38426 preview

CVE-2026-38426

GitHubsermikr0/cve-2026-38426

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+4
4 months ago
CVE-2026-38422 preview

CVE-2026-38422

GitHubsermikr0/cve-2026-38422

CVE-2026-38422 — Remote Code Execution via Combined Buffer Overflows in Tasmota fetch_jpg() (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+5
4 months ago
CVE-2023-33869-RCE-PoC preview

CVE-2023-33869-RCE-PoC

GitHubnap3xd/cve-2023-33869-rce-poc

Remote Code Execution (RCE) proof of concept on a enphase solar inverter

command-and-controlembedded-systems-securityexploitation+3
7 months ago
Previous123Next