Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
197 results
CVE-2026-90847 preview

CVE-2026-90847

GitHubshlln/cve-2026-90847

Proof-of-concept for CVE-2026-90847, an authenticated RCE in iux_set.cgi via malicious .cfg tar upload that writes commands into crontab for…

embedded-systems-securityexploitationiot-security+5
7 days ago
CVE-2026-94095 preview

CVE-2026-94095

GitHubhackspeak/cve-2026-94095

PoC for CVE-2026-94095, a traceroute command injection in Netcore NBR200V2 firmware via ubus JSON-RPC, enabling root RCE for authorized testing.

embedded-systems-securityexploitationhardware-iot-security+5
111 days ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
21 month ago
CVE-2026-93958 preview

CVE-2026-93958

GitHubhackspeak/cve-2026-93958

Authenticated command injection PoC for D-Link R95/BE9500 DHMAPI SetTimeSettings, achieving root RCE via NTPServer backtick injection, with full…

command-and-controlembedded-systems-securityexploitation+7
412 days ago
Vulnerability-DLink-CVE-2025-14659 preview

Vulnerability-DLink-CVE-2025-14659

GitHubpeterlinccl/vulnerability-dlink-cve-2025-14659

Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in…

embedded-systems-securityexploitationfirmware-analysis+6
19 days ago
cve-2026-19900-PoC preview

cve-2026-19900-PoC

GitHubon3sk-0x1/cve-2026-19900-poc

Proof-of-concept exploit for CVE-2026-19900, an authentication bypass and remote code execution vulnerability in LB-LINK X-PRO routers, allowing…

authenticationexploitationiot-security+3
28 days ago
CVE-2026-82539 preview

CVE-2026-82539

GitHubxernary/cve-2026-82539

Security advisory for TOTOLINK a720r buffer overflow vulnerability

binary-exploitationembedded-systems-securityexploitation+5
420 days ago
CVE-2026-15469 preview

CVE-2026-15469

GitHubtony102741/cve-2026-15469

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

authenticationcryptographyexploitation+5
21 month ago
Terrminus-CVE-2026-2406 preview

Terrminus-CVE-2026-2406

GitHubridpath/terrminus-cve-2026-2406

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

exploitationinformation-gatheringiot-security+8
28 months ago
CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown preview

CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown

GitHubmbanyamer/cve-2026-26235-jung-smart-visu-server-unauthenticated-reboot-shutdown

Proof-of-concept exploit for CVE-2026-26235, an unauthenticated denial-of-service vulnerability in JUNG Smart Visu Server <=1.1.1050, allowing remote…

exploitationiot-securitypenetration-testing+2
7 months ago
CVE-2023-51073 preview

CVE-2023-51073

GitHubchristopher-pace/cve-2023-51073

Firmware Update Server Verification Vulnerability on Buffalo LS210D Version 1.78-0.03

exploitationfirmware-analysishardware-iot-security+3
2 years ago
exploit-CVE-2026-2670 preview

exploit-CVE-2026-2670

GitHubali-py3/exploit-cve-2026-2670

Proof-of-concept exploit for CVE-2026-2670, a command injection vulnerability in Advantech WISE-6610 routers, allowing authenticated attackers to…

command-and-controlexploitationiot-security+3
7 months ago
device_renesas_kernel_AOSP10_r33_CVE-2021-33034 preview

device_renesas_kernel_AOSP10_r33_CVE-2021-33034

GitHubtrinadh465/device_renesas_kernel_aosp10_r33_cve-2021-33034

Kernel source tree for Renesas AOSP10 R33 with a patch for CVE-2021-33034, addressing a use-after-free vulnerability in the Bluetooth HCI event…

embedded-systems-securityiot-securityvulnerability-analysis
4 years ago
CVE-2026-76071 preview

CVE-2026-76071

GitHubozcanpng/cve-2026-76071

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

binary-analysisexploitationfirmware-analysis+3
119 days ago
the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt preview

the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

GitHubhunt-benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

authenticationcryptographyexploitation+4
1 month ago
ghostlock-cve-2026-43499 preview

ghostlock-cve-2026-43499

GitHubgitchw/ghostlock-cve-2026-43499

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

binary-exploitationembedded-systems-securityexploitation+5
210 days ago
CVE-2026-25938-FUXA-Unauthenticated-RCE preview

CVE-2026-25938-FUXA-Unauthenticated-RCE

GitHubjudgedbykira/cve-2026-25938-fuxa-unauthenticated-rce

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

exploitationiot-securitypayload-development+6
11 month ago
FirmAE preview

FirmAE

GitHubpr0v3rbs/firmae

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

dynamic-analysis-sandboxingembedded-systems-securityfirmware-analysis+3
9443 months ago
Previous12…11Next