Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
CVE-2022-45701 preview

CVE-2022-45701

GitHubyerodin/cve-2022-45701

Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) POC Exploit (CVE-2022-45701)

exploitationpenetration-testingred-teaming+3
7
3 years ago
CVE-2021-27246_Pwn2Own2020 preview

CVE-2021-27246_Pwn2Own2020

GitHubsynacktiv/cve-2021-27246_pwn2own2020

Exploit code for CVE-2021-27246 targeting TPLink Archer routers, demonstrated at Pwn2Own 2020 Tokyo. Includes proof-of-concept for remote code…

embedded-systems-securityexploitationhardware-iot-security+3
435 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubceh-aditya-raj/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…

educationexploitationpayload-development+5
29 months ago
CVE-2018-20162-digi-lr54-restricted-shell-escape preview

CVE-2018-20162-digi-lr54-restricted-shell-escape

GitHubstigtsp/cve-2018-20162-digi-lr54-restricted-shell-escape

Proof-of-concept exploit for CVE-2018-20162: sandbox escape in Digi TransPort LR54 LTE router via SIGINT handling flaw, yielding root shell access.

embedded-systems-securityexploitationhardware-iot-security+5
7 years ago
ble_norton_core preview

ble_norton_core

GitHubembedi/ble_norton_core

Proof-of-concept exploit demonstrating command injection via BLE service in Norton Core Secure WiFi Router (CVE-2018-5234). Includes SSH access setup…

bluetooth-securityexploitationhardware-security+5
318 years ago
CVE-2025-55182-exp preview

CVE-2025-55182-exp

GitHubspritualkb/cve-2025-55182-exp

CVE-2025-55182 React Server Components Remote Code Execution Exploit Tool

ctfeducationexploitation+6
469 months ago
cve-2025-29384 preview

cve-2025-29384

GitHubfomovet/cve-2025-29384

POC for CVE-2025-29384

binary-exploitationeducationembedded-systems-security+8
3 months ago
reverse-skill preview

reverse-skill

GitHubzhaoxuya520/reverse-skill

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

ai-securitybinary-analysisctf+8
37.8k4 days ago
poisontap preview

poisontap

GitHubsamyk/poisontap

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

authenticationcommand-and-controldata-exfiltration+7
6.5k7 years ago
CVE-2023-43482 preview

CVE-2023-43482

GitHubmr-xn/cve-2023-43482

TP-Link ER7206 Omada Gigabit VPN Router uhttpd freeStrategy Command injection Vulnerability

command-and-controlexploitationpenetration-testing+3
62 years ago
CVE-2022-25061 preview

CVE-2022-25061

GitHubexploitwritter/cve-2022-25061

This script exploits a remote command execution vulnerability under the oal_setIp6DefaultRoute component in the TPLink WR840N router.

exploitationpenetration-testingred-teaming+2
24 years ago
CVE-2026-26898-Xiaomi-SSRF-HostHeaderInjection preview

CVE-2026-26898-Xiaomi-SSRF-HostHeaderInjection

GitHubiwallplace/cve-2026-26898-xiaomi-ssrf-hostheaderinjection

Unauthenticated SSRF in Xiaomi Mi Router 4A Gigabit Edition (firmware 3.0.24) via Host Header Injection — CVE-2026-26898

exploitationnetwork-securitypenetration-testing+3
13 months ago
CVE-2023-51119 preview

CVE-2023-51119

GitHuboscarakaelvis/cve-2023-51119

Improper Access Control on D-Link DIR-605L router

exploitationiot-securitypenetration-testing+3
12 years ago
refresh preview

refresh

GitHubbattleofthebots/refresh

CVE-2022-1388 - F5 Router RCE Replica

educationexploitationpenetration-testing+3
2 years ago
CVE-2022-25063 preview

CVE-2022-25063

GitHubexploitwritter/cve-2022-25063

This script exploits a vulnerability (XSS) in the TPLink WR840N router, using a field for injecting javascript code.

exploitationinformation-gatheringpenetration-testing+3
4 years ago
sshuttle preview

sshuttle

GitHubapenwarr/sshuttle

Wrong project! You should head over to http://github.com/sshuttle/sshuttle

network-securitypenetration-testingred-teaming+2
8.9k10 years ago
rpef preview

rpef

GitHubmncoppola/rpef

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

embedded-systems-securityexploitationfirmware-analysis+6
12412 years ago
CVE-2023-1389 preview

CVE-2023-1389

GitHubvoyag3r-security/cve-2023-1389

Proof-of-concept scripts for CVE-2023-1389, an unauthenticated command injection in TP-Link Archer AX21, providing file transfer and reverse shell…

command-and-controlexploitationpayload-development+4
173 years ago
Previous12Next