Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
104 results
CVE-2022-45599 preview

CVE-2022-45599

GitHubethancunt/cve-2022-45599

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

authenticationexploitationpassword-attacks+3
3 years ago
CVE-2022-25062 preview

CVE-2022-25062

GitHubexploitwritter/cve-2022-25062

This script exploits a vulnerability (IoF) in the TPLink WR840N router, using a field for injecting code in the module DNS.

exploitationhardware-iot-securityiot-security+3
4 years ago
CVE-2024-33111 preview

CVE-2024-33111

GitHubfallenskill1/cve-2024-33111

D-Link DIR-845L router is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2022-25063 preview

CVE-2022-25063

GitHubexploitwritter/cve-2022-25063

This script exploits a vulnerability (XSS) in the TPLink WR840N router, using a field for injecting javascript code.

exploitationinformation-gatheringpenetration-testing+3
4 years ago
UltramanGaia preview

UltramanGaia

GitHubajaymt6/ultramangaia

A login bypass(CVE-2019-18371) and a command injection vulnerability(CVE-2019-18370) in Xiaomi Router R3G up to versi…

exploitationiot-securitypenetration-testing+2
4 years ago
TP-Link-ArcherC5-RCE preview

TP-Link-ArcherC5-RCE

GitHubjackdoan/tp-link-archerc5-rce

CVE-2018-19537

command-and-controlembedded-systems-securityexploitation+8
207 years ago
sshuttle preview

sshuttle

GitHubapenwarr/sshuttle

Wrong project! You should head over to http://github.com/sshuttle/sshuttle

network-securitypenetration-testingred-teaming+2
8.9k10 years ago
rpef preview

rpef

GitHubmncoppola/rpef

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

embedded-systems-securityexploitationfirmware-analysis+6
12412 years ago
sncscan preview

sncscan

GitHubusdag/sncscan

Tool for analyzing SAP Secure Network Communications (SNC).

configuration-auditingnetwork-securitypenetration-testing+1
612 years ago
CVE-2023-1389 preview

CVE-2023-1389

GitHubvoyag3r-security/cve-2023-1389

Proof-of-concept scripts for CVE-2023-1389, an unauthenticated command injection in TP-Link Archer AX21, providing file transfer and reverse shell…

command-and-controlexploitationpayload-development+4
173 years ago
cve-2022-22947 preview

cve-2022-22947

GitHubtwseptian/cve-2022-22947

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

command-and-controlexploitationpayload-generation+3
114 years ago
CVE-2026-11834 preview

CVE-2026-11834

GitHubmattgsys/cve-2026-11834

Proof of Concept (PoC) for the TP-Link DHCP Option 66 Unauthenticated RCE (CVE-2026-11834)

command-and-controlexploitationpayload-generation+3
43 months ago
CVE-2025-55182-Exploiter preview

CVE-2025-55182-Exploiter

GitHubalfazhossain/cve-2025-55182-exploiter

CVE-2025-55182-Exploiter Google Chrome Extension. nextjs vulnerability #nextjscve

exploitationinformation-gatheringpenetration-testing+3
49 months ago
CVE-2023-38120 preview

CVE-2023-38120

GitHubwarber0x/cve-2023-38120

Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability

command-and-controlexploitationpenetration-testing+2
32 years ago
CVE-2020-29669 preview

CVE-2020-29669

GitHubcode-byter/cve-2020-29669

Macally WIFISD2

embedded-systems-securityexploitationhardware-iot-security+5
25 years ago
CVE-2023-47464 preview

CVE-2023-47464

GitHubhadesscs/cve-2023-47464

CVE-2023-47464 POC

educationexploitationpenetration-testing+3
22 years ago
nepstech-xpon-router-CVE-2024-40119 preview

nepstech-xpon-router-CVE-2024-40119

GitHubbaroi-ai/nepstech-xpon-router-cve-2024-40119

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

exploitationiot-securitypenetration-testing+3
22 years ago
CVE-2025-26202-Details preview

CVE-2025-26202-Details

GitHuba17-ba/cve-2025-26202-details

CVE-2025-26202

exploitationinformation-gatheringpenetration-testing+3
21 year ago
Previous123456Next