Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
306 results
CVE-2026-95675 preview

CVE-2026-95675

GitHubd6fault/cve-2026-95675

Python PoC exploiting CVE-2026-95675, an unauthenticated root command injection in D-Link DAP-1360 RevB firmware via a hardcoded auth-bypass and the…

embedded-systems-securityexploitationfirmware-analysis+6
1
4 days ago
CVE-2026-96515 preview

CVE-2026-96515

GitHubwhoami-012/cve-2026-96515

Technical report and authenticated reverse-shell PoC for CVE-2026-96515, a root command execution flaw in the Netlink HG323RW router's BOA diagnostic…

binary-analysisembedded-systems-securityexploitation+7
4 days ago
CVE-2026-90847 preview

CVE-2026-90847

GitHubshlln/cve-2026-90847

Proof-of-concept for CVE-2026-90847, an authenticated RCE in iux_set.cgi via malicious .cfg tar upload that writes commands into crontab for…

embedded-systems-securityexploitationiot-security+5
5 days ago
CVE-2024-29269 preview

CVE-2024-29269

GitHubdkstar11q/cve-2024-29269

Exploit for CVE-2024-29269 enabling unauthenticated OS command execution on TLR-2005KSH routers, with ZoomEye and Leakix dork queries for target…

embedded-systems-securityexploitationinformation-gathering+5
2 years ago
CVE-2026-94095 preview

CVE-2026-94095

GitHubhackspeak/cve-2026-94095

PoC for CVE-2026-94095, a traceroute command injection in Netcore NBR200V2 firmware via ubus JSON-RPC, enabling root RCE for authorized testing.

embedded-systems-securityexploitationhardware-iot-security+5
17 days ago
CVE-2026-93958 preview

CVE-2026-93958

GitHubhackspeak/cve-2026-93958

Authenticated command injection PoC for D-Link R95/BE9500 DHMAPI SetTimeSettings, achieving root RCE via NTPServer backtick injection, with full…

command-and-controlembedded-systems-securityexploitation+7
48 days ago
cve-2025-55182-lab preview

cve-2025-55182-lab

GitHubabhaybansal16/cve-2025-55182-lab

Docker-based lab reproducing CVE-2025-55182 (React2Shell), an unauthenticated RCE in React Server Components Flight Protocol, with PoC exploit and…

container-securityeducationexploitation+6
8 days ago
CVE-2026-12944 preview

CVE-2026-12944

GitHubshadowforge-cyber/cve-2026-12944

Python PoC exploiting CVE-2026-12944, an SSRF in Langflow 1.10.0 via urllib in custom components, with authenticated read and fetch capabilities.

api-securityexploitationpenetration-testing+3
11 days ago
CVE-2026-13181-Telerik preview

CVE-2026-13181-Telerik

GitHubivanesk315/cve-2026-13181-telerik

Proof-of-concept exploit for CVE-2026-13181 affecting Telerik web components, demonstrating remote code execution via crafted requests.

exploitationpenetration-testingvulnerability-analysis+2
18 days ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubr3vpwnx/cve-2025-55182

Standalone exploit for CVE-2025-55182 achieving unauthenticated RCE in Next.js App Router via React Server Components Flight deserialization, with…

exploitationpayload-developmentpenetration-testing+3
20 days ago
misfortune-cookie preview

misfortune-cookie

GitHubluel-4013/misfortune-cookie

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

binary-exploitationembedded-systems-securityexploitation+6
21 days ago
CVE-2026-56718 preview

CVE-2026-56718

GitHubhellkkid/cve-2026-56718

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

embedded-systems-securityexploitationiot-security+3
24 days ago
CVE-2025-66478-PoC-Reverse-Shell preview

CVE-2025-66478-PoC-Reverse-Shell

GitHubjotaespig/cve-2025-66478-poc-reverse-shell

Proof-of-concept exploit for CVE-2025-55182/66478, a React Server Components deserialization RCE, delivering a reverse shell via crafted multipart…

exploitationpayload-developmentpenetration-testing+3
128 days ago
CVE-2026-82539 preview

CVE-2026-82539

GitHubxernary/cve-2026-82539

Security advisory for TOTOLINK a720r buffer overflow vulnerability

binary-exploitationembedded-systems-securityexploitation+5
416 days ago
CVE-2026-23869 preview

CVE-2026-23869

GitHubyohannslm/cve-2026-23869

Proof-of-concept exploit for CVE-2026-23869, a denial-of-service vulnerability in React Server Components allowing unauthenticated CPU exhaustion via…

exploitationvulnerability-analysisweb-application-exploitation+1
5 months ago
tapo-c260-rce preview

tapo-c260-rce

GitHubl0lsec/tapo-c260-rce

PoC exploit chain for TP-Link Tapo C260 camera — CVE-2026-0651/0652/0653. Research by @spaceraccoon.

command-and-controlembedded-systems-securityexploitation+7
26 months ago
CVE-2026-23869-Exploit preview

CVE-2026-23869-Exploit

GitHubcybertechajju/cve-2026-23869-exploit

Automated exploit tool for CVE-2026-23869, a remote DoS in React Server Components. Includes PoC, Nuclei template, and scanning scripts for detection…

exploitationpenetration-testingreconnaissance+3
95 months ago
CVE-2026-30863-Exploit preview

CVE-2026-30863-Exploit

GitHubworthes/cve-2026-30863-exploit

CWE-287: Improper Authentication in parse-community parse-server

authenticationexploitationpenetration-testing+2
6 months ago
Previous12…17Next