Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
CVE-2026-64824-PoC preview

CVE-2026-64824-PoC

GitHubboreas37/cve-2026-64824-poc

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

exploitationiot-securitypayload-development+2
1
4 days ago
hikihack preview

hikihack

GitHubxjghnxhlh/hikihack

Exploits Hikvision CVE-2017-7921 to demonstrate unauthenticated credential disclosure and admin interface exposure, promoting patches and secure…

educationexploitationinformation-gathering+3
22 days ago
netgear-telenetenable preview

netgear-telenetenable

GitHubinsanid/netgear-telenetenable

Lightweight Python utility to enable telnet on Netgear routers (R7000, R7500) using LAN MAC and admin credentials. Useful for penetration testing,…

embedded-systems-securityexploitationhardware-iot-security+3
963 years ago
tplink-CVE-2017-11519 preview

tplink-CVE-2017-11519

GitHubvakzz/tplink-cve-2017-11519

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

exploitationiot-securitypenetration-testing+3
48 years ago
CVE-2026-54477 preview

CVE-2026-54477

GitHubmichaeladamgroberman/cve-2026-54477

CVE-2026-54477 disclosure detailing missing security headers (CSP, X-Frame-Options) in Gardyn IoT admin panel enabling clickjacking and XSS, with…

iot-securitymisconfigurationvulnerability-analysis+1
1 month ago
CVE-2026-28767 preview

CVE-2026-28767

GitHubmichaeladamgroberman/cve-2026-28767

CVE-2026-28767 disclosure: missing authentication on Gardyn Home Kit cloud API admin notifications endpoint, exposing internal system data and…

api-securitycloud-securityiot-security+3
2 months ago
CVE-2025-45619 preview

CVE-2025-45619

GitHubweedl/cve-2025-45619

Proof-of-concept exploit for CVE-2025-45619, an information disclosure vulnerability in AVer PTC310UV2 camera firmware that exposes plaintext admin…

exploitationinformation-gatheringiot-security+3
1 year ago
CVE-2025-41646---Critical-Authentication-Bypass- preview

CVE-2025-41646---Critical-Authentication-Bypass-

GitHubgreenforcenetworks/cve-2025-41646---critical-authentication-bypass-

Proof-of-concept exploit for CVE-2025-41646, a critical authentication bypass in RevPi WebStatus ≤ v2.4.5, exploiting weak type comparison to gain…

authentication-authorizationexploitationids-ips-evasion+5
11 year ago
CVE-2025-1738 preview

CVE-2025-1738

GitHubn0n4m3x41/cve-2025-1738

Proof-of-concept exploit for CVE-2025-1738 demonstrating cleartext admin password exposure in Trivision NC227WF cameras via unauthenticated local…

educationexploitationhardware-iot-security+3
4 months ago
CVE-2024-40617 preview

CVE-2024-40617

GitHubkyssk00l/cve-2024-40617

Proof-of-concept exploit for CVE-2024-40617 targeting Fujitsu M2M GW1500 IoT gateway. Provides remote exploitation via admin password authentication…

embedded-systems-securityexploitationiot-security+3
72 years ago
WantasticCore preview

WantasticCore

GitHubwantasticapp/wantasticcore

Self-hosted WireGuard mesh VPN with browser-based admin portal, Winbox proxy, WebSSH, and WebProxy for managing remote devices and IoT infrastructure…

ai-securityauthenticationcloud-security+6
141 month ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
3 months ago
CVE-2022-31269 preview

CVE-2022-31269

GitHubomarhashem123/cve-2022-31269

Proof-of-concept exploit for CVE-2022-31269 targeting Nortek Linear eMerge E3-Series, enabling information disclosure to access the admin dashboard.

exploitationinformation-gatheringiot-security+3
13 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubgabrielavls/cve-2017-7921

Exploit script for CVE-2017-7921 targeting vulnerable IP cameras. Retrieves admin credentials via config decryption and enables automated snapshot…

exploitationinformation-gatheringiot-security+3
2 years ago
CVE-2017-14262 preview

CVE-2017-14262

GitHubzzz66686/cve-2017-14262

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

embedded-systems-securityexploitationiot-security+3
68 years ago
CVE-2017-14263 preview

CVE-2017-14263

GitHubzzz66686/cve-2017-14263

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

authenticationexploitationiot-security+3
58 years ago
CVE-2025-48461 preview

CVE-2025-48461

GitHubjoelczk/cve-2025-48461

Technical disclosure of a predictable session cookie vulnerability (CVE-2025-48461) in Advantech WISE-4060 IoT portal, enabling bruteforce…

authenticationexploitationiot-security+3
1 year ago
CVE-2020-14965 preview

CVE-2020-14965

GitHubg-rubert/cve-2020-14965

TP-LINK Multiple HTML Injection Vulnerabilities

embedded-systems-securityhardware-securityiot-security+3
5 years ago
Previous12Next