Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
64 results
CVE-2024-24919-CHECKPOINT preview

CVE-2024-24919-CHECKPOINT

GitHubj4f9s5d2q7/cve-2024-24919-checkpoint

Exploit scanner for CVE-2024-24919 targeting Check Point Security Gateways. Scans IP lists, extracts /etc/passwd, /etc/shadow, and system logs from…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
Symfony-CVE-Scanner-PoC- preview

Symfony-CVE-Scanner-PoC-

GitHubmoften/symfony-cve-scanner-poc-

CVE-2021-21424 - CRLF Injection - CVE-2021-41268 - Host Header Injection - CVE-2022-24894 - WebProfiler abierto - CVE-2019-10909 - Directory Traversal

exploitationinformation-gatheringpenetration-testing+3
1 year ago
Internet-Security-Project---CVE-2021-26814 preview

Internet-Security-Project---CVE-2021-26814

GitHubpaolorabbito/internet-security-project---cve-2021-26814

Educational exploit demonstration for CVE-2021-26814 targeting Wazuh v4.0.3, with step-by-step exploitation and remediation code for university-level…

code-analysiseducationexploitation+3
4 years ago
dref preview

dref

GitHubreverseclabs/dref

DNS Rebinding Exploitation Framework

dns-analysisexploitationiot-security+3
4945 years ago
SecureTea-Project preview

SecureTea-Project

GitHubowasp/securetea-project

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

defensive-toolsintrusion-detectioniot-security+4
3023 years ago
cve-2020-9375 preview

cve-2020-9375

GitHubthewhiteh4t/cve-2020-9375

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header…

exploitationhardware-iot-securityiot-security+2
206 years ago
CVE-2021-40859 preview

CVE-2021-40859

GitHubpussycat0x/cve-2021-40859

Auerswald VoIP System Secret Backdoors -PoC

exploitationhardware-securityiot-security+3
54 years ago
CVE-2026-19745 preview

CVE-2026-19745

GitHubdrbloop2000/cve-2026-19745

Learn how I found my first two CVEs by pure accident.

exploitationiot-securityvulnerability-analysis+1
21 month ago
TP-Link-Archer-CR-700-XSS-Exploit preview

TP-Link-Archer-CR-700-XSS-Exploit

GitHubayushman4/tp-link-archer-cr-700-xss-exploit

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

exploitationiot-securitypenetration-testing+3
310 years ago
HTC preview

HTC

GitHubwmasday/htc

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

exploitationiot-securitypassword-attacks+3
33 years ago
CVE-2026-25938-FUXA-Unauthenticated-RCE preview

CVE-2026-25938-FUXA-Unauthenticated-RCE

GitHubjudgedbykira/cve-2026-25938-fuxa-unauthenticated-rce

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

exploitationiot-securitypayload-development+6
11 month ago
XSS-CVE-2022-30489 preview

XSS-CVE-2022-30489

GitHubbadboycxcc/xss-cve-2022-30489

Proof-of-concept exploit for CVE-2022-30489, a stored XSS vulnerability in WAVLINK WN535G3 routers, demonstrating a POST-based attack via the…

exploitationiot-securitypenetration-testing+3
24 years ago
CVE-2021-35296 preview

CVE-2021-35296

GitHubafaq1337/cve-2021-35296

PoC of CVE-2021-35296 - PTCL Modem HG150-Ub

exploitationiot-securitypenetration-testing+2
22 years ago
nepstech-xpon-router-CVE-2024-40119 preview

nepstech-xpon-router-CVE-2024-40119

GitHubbaroi-ai/nepstech-xpon-router-cve-2024-40119

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

exploitationiot-securitypenetration-testing+3
22 years ago
CVE-2026-28767 preview

CVE-2026-28767

GitHubmichaeladamgroberman/cve-2026-28767

CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securitycloud-securityiot-security+3
4 months ago
CVE-2026-54477 preview

CVE-2026-54477

GitHubmichaeladamgroberman/cve-2026-54477

CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)

iot-securitymisconfigurationvulnerability-analysis+1
3 months ago
CVE-2024-55040-Sensaphone-XSS preview

CVE-2024-55040-Sensaphone-XSS

GitHubtcbutler320/cve-2024-55040-sensaphone-xss

Public disclose of several stored XSS vulnerabilities in the Sensaphone WEB600 (CVE-2024-55040)

exploitationiot-securitypenetration-testing+3
11 year ago
CVE-2025-67159 preview

CVE-2025-67159

GitHubremenis/cve-2025-67159

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

authenticationexploitationhardware-iot-security+3
9 months ago
Previous1234Next