Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
CVE-2017-14262 preview

CVE-2017-14262

GitHubzzz66686/cve-2017-14262

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

embedded-systems-securityexploitationiot-security+3
6
8 years ago
CVE-2017-14263 preview

CVE-2017-14263

GitHubzzz66686/cve-2017-14263

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

authenticationexploitationiot-security+3
58 years ago
tplink-CVE-2017-11519 preview

tplink-CVE-2017-11519

GitHubvakzz/tplink-cve-2017-11519

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

exploitationiot-securitypenetration-testing+3
48 years ago
CVE-2022-37932 preview

CVE-2022-37932

GitHubtim-hoekstra/cve-2022-37932

Proof-of-concept exploit for an authentication bypass in HP 1920 Series switches, allowing unauthenticated admin password change via crafted HTTP…

educationexploitationiot-security+3
21 year ago
nepstech-xpon-router-CVE-2024-40119 preview

nepstech-xpon-router-CVE-2024-40119

GitHubbaroi-ai/nepstech-xpon-router-cve-2024-40119

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

exploitationiot-securitypenetration-testing+3
12 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubgabrielavls/cve-2017-7921

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

exploitationinformation-gatheringiot-security+3
3 years ago
cve-2018-9995 preview

cve-2018-9995

GitHubdearpan/cve-2018-9995

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

exploitationiot-securitypassword-attacks+2
4 years ago
WantasticCore preview

WantasticCore

GitHubwantasticapp/wantasticcore

AIO Cloud Managment Server

ai-securityauthenticationcloud-security+6
141 month ago
CVE-2026-64824-PoC preview

CVE-2026-64824-PoC

GitHubboreas37/cve-2026-64824-poc

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

exploitationiot-securitypayload-development+2
112 days ago
CVE-2025-41646---Critical-Authentication-Bypass- preview

CVE-2025-41646---Critical-Authentication-Bypass-

GitHubgreenforcenetworks/cve-2025-41646---critical-authentication-bypass-

CVE-2025-41646 - Critical Authentication bypass

authentication-authorizationexploitationids-ips-evasion+5
11 year ago
CamOver preview

CamOver

GitHubentysec/camover

CamOver is a camera exploitation tool that allows to disclosure network camera admin password.

exploitationinformation-gatheringiot-security+1
5962 years ago
RomBuster preview

RomBuster

GitHubentysec/rombuster

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

exploitationinformation-gatheringiot-security+1
5592 years ago
CVE-2026-32646 preview

CVE-2026-32646

GitHubmichaeladamgroberman/cve-2026-32646

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securityauthenticationcloud-security+6
2 months ago
CVE-2026-28767 preview

CVE-2026-28767

GitHubmichaeladamgroberman/cve-2026-28767

CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securitycloud-securityiot-security+3
2 months ago
CVE-2026-54477 preview

CVE-2026-54477

GitHubmichaeladamgroberman/cve-2026-54477

CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)

iot-securitymisconfigurationvulnerability-analysis+1
2 months ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
13 months ago
CVE-2025-48461 preview

CVE-2025-48461

GitHubjoelczk/cve-2025-48461

Technical disclosure of a predictable session cookie vulnerability (CVE-2025-48461) in Advantech WISE-4060 IoT portal, enabling bruteforce…

authenticationexploitationiot-security+3
1 year ago
hichipreset preview
Archived

hichipreset

GitHubprisect/hichipreset

Hicip IP admin password reset script using CVE-2020-9529. This is made for educational purposes only of course.

educationexploitationiot-security+2
1 year ago
Previous12Next