Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
242 results
buds-audit preview

buds-audit

GitHubspiritualmachines/buds-audit

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

bluetooth-securityembedded-systems-securityexploitation+8
1
2 months ago
cve-2016-1555 preview

cve-2016-1555

GitHubide0x90/cve-2016-1555

Metasploit module exploiting unauthenticated command injection in multiple Netgear router models to achieve remote code execution with root…

embedded-systems-securityexploitationexploit-frameworks+5
27 years ago
Quiksand-CVE-2023-24012 preview

Quiksand-CVE-2023-24012

GitHubsafelock-d2e/quiksand-cve-2023-24012

Proof-of-concept demonstrating a permission bypass in ROS 2 SROS2 security framework, allowing unauthorized topic subscription via modified…

embedded-systems-securityexploitationiot-security+3
27 months ago
JXL_Infotainment_CVE-2025-69515 preview

JXL_Infotainment_CVE-2025-69515

GitHubthorat-shubham/jxl_infotainment_cve-2025-69515

Proof-of-concept exploit for CVE-2025-69515 demonstrating static GPS spoofing on JXL 9-inch Android infotainment units via SDR-based signal…

embedded-systems-securityexploitationhardware-iot-security+4
5 months ago
CVE-2026-32743-PX4-Autopilot-MavlinkLogHandler-Stack-Buffer-Overflow-DoS- preview

CVE-2026-32743-PX4-Autopilot-MavlinkLogHandler-Stack-Buffer-Overflow-DoS-

GitHubmbanyamer/cve-2026-32743-px4-autopilot-mavlinkloghandler-stack-buffer-overflow-dos-

A remote Denial of Service (DoS) exploit for PX4 Autopilot versions ≤1.17.0-rc2 via a stack‑based buffer overflow in the MavlinkLogHandler.

binary-exploitationembedded-systems-securityexploitation+3
4 months ago
CVE-2021-4045 preview

CVE-2021-4045

GitHubkaleth4/cve-2021-4045

Command injection exploit for TP-Link Tapo C200 camera (CVE-2021-4045) providing root shell access via UART and reverse-engineered uhttpd binary…

command-and-controlembedded-systems-securityexploitation+6
3 months ago
CVE-2026-38426 preview

CVE-2026-38426

GitHubsermikr0/cve-2026-38426

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+4
4 months ago
T3-Technology-CPE-Advisories preview

T3-Technology-CPE-Advisories

GitHubpwnonu/t3-technology-cpe-advisories

CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE

embedded-systems-securityexploitationhardware-security+5
3 months ago
CVE-2018-14847 preview

CVE-2018-14847

GitHubthemalwareguardian/cve-2018-14847

Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the…

embedded-systems-securityexploitationinformation-gathering+3
5 months ago
ASUS-AiCloud-RCE preview

ASUS-AiCloud-RCE

GitHubmurrez/asus-aicloud-rce

SETROOTCERTIFICATE (write /etc/cert.pem.1) + APPLYAPP (RC_SERVICE execution). Refs: CVE-2025-2492, CVE-2024-12912, CVE-2025-59366; runZero;…

embedded-systems-securityexploitationiot-security+4
4 months ago
CVE-2026-32707-PX4-Autopilot-tattu_can-Stack-Buffer-Overflow-DoS- preview

CVE-2026-32707-PX4-Autopilot-tattu_can-Stack-Buffer-Overflow-DoS-

GitHubmbanyamer/cve-2026-32707-px4-autopilot-tattu_can-stack-buffer-overflow-dos-

Proof-of-concept exploit for CVE-2026-32707, a stack buffer overflow in the PX4-Autopilot tattu_can driver, causing denial of service via crafted CAN…

binary-exploitationembedded-systems-securityexploitation+4
4 months ago
CVE-2026-38422 preview

CVE-2026-38422

GitHubsermikr0/cve-2026-38422

CVE-2026-38422 — Remote Code Execution via Combined Buffer Overflows in Tasmota fetch_jpg() (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+5
4 months ago
CVE-2026-38698-and-CVE-2026-38699 preview

CVE-2026-38698-and-CVE-2026-38699

GitHubvital-information-resource-under-siege/cve-2026-38698-and-cve-2026-38699

Technical details and publication about CVE-2026-38698 and CVE-2026-38699

binary-exploitationembedded-systems-securityexploitation+5
4 months ago
CVE-2026-36522 preview

CVE-2026-36522

GitHubdeepwoodssec/cve-2026-36522

Proof-of-concept exploit for CVE-2026-36522: unauthenticated NaN injection via MAVLink PARAM_SET in ArduPilot ArduPlane, causing DoS or silent…

embedded-systems-securityexploitationfuzzing+3
3 months ago
CVE-2026-38427 preview

CVE-2026-38427

GitHubsermikr0/cve-2026-38427

CVE-2026-38427 — Integer Wraparound → Heap Buffer Overflow in Tasmota fetch_jpg() uint16_t (Tasmota <= 15.3.0.3)

binary-exploitationembedded-systems-securityexploitation+4
4 months ago
CVE-2025-69821-Beat-XP-Vega-Smartwatch-Security-Assessment preview

CVE-2025-69821-Beat-XP-Vega-Smartwatch-Security-Assessment

GitHubcipherx1802/cve-2025-69821-beat-xp-vega-smartwatch-security-assessment

A security assessment of the Beat XP VEGA Smartwatch (Firmware RB303ATV006229) focused on Bluetooth Low Energy (BLE) connectivity revealed a design…

bluetooth-securityembedded-systems-securityexploitation+6
5 months ago
CVE-2018-18852 preview

CVE-2018-18852

GitHubandripwn/cve-2018-18852

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.

embedded-systems-securityexploitationiot-security+4
17 years ago
CVE-2026-36438 preview

CVE-2026-36438

GitHubkensh1k/cve-2026-36438

Documentation of CVE-2026-36438: a vulnerability in Intelbras VIP 1230 B/D G4 devices allowing remote attackers to obtain administrator account…

authenticationembedded-systems-securityinformation-gathering+3
4 months ago
Previous1…8910…14Next