Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
ufuzz preview

ufuzz

GitHubphikshun/ufuzz

Automated UPnP fuzzing tool for discovering vulnerabilities in embedded systems, with HTTP fuzzing support and custom crash monitoring.

embedded-systems-securityfuzzingiot-security+3
41
6 years ago
CVE-2025-63820 preview

CVE-2025-63820

GitHubxernary/cve-2025-63820

Proof-of-concept of vulnerability found in Totolink A720R router

embedded-systems-securityexploitationhardware-iot-security+3
9 months ago
HENlo preview

HENlo

GitHubtheofficialflow/henlo

WebKit+Kernel exploit chain for all PS Vita firmwares

binary-exploitationembedded-systems-securityexploitation+2
2373 years ago
Genzai preview

Genzai

GitHubumair9747/genzai

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

iot-securitypassword-attackspenetration-testing+3
2081 year ago
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityexploitationiot-security+5
113 days ago
CVE-2026-25938-FUXA-Unauthenticated-RCE preview

CVE-2026-25938-FUXA-Unauthenticated-RCE

GitHubjudgedbykira/cve-2026-25938-fuxa-unauthenticated-rce

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

exploitationiot-securitypayload-development+6
112 days ago
CVE-2026-8023 preview

CVE-2026-8023

GitHubret2c/cve-2026-8023

Proof-of-concept exploit for pre-authentication path traversal in Zephyr RTOS HTTP server static-fs handler, demonstrating directory traversal via…

embedded-systems-securityexploitationiot-security+3
2 months ago
CVE-2026-54477 preview

CVE-2026-54477

GitHubmichaeladamgroberman/cve-2026-54477

CVE-2026-54477 disclosure detailing missing security headers (CSP, X-Frame-Options) in Gardyn IoT admin panel enabling clickjacking and XSS, with…

iot-securitymisconfigurationvulnerability-analysis+1
1 month ago
CVE-2026-36438 preview

CVE-2026-36438

GitHubkensh1k/cve-2026-36438

Documentation of CVE-2026-36438: a vulnerability in Intelbras VIP 1230 B/D G4 devices allowing remote attackers to obtain administrator account…

authenticationembedded-systems-securityinformation-gathering+3
3 months ago
TP-Link-Archer-CR-700-XSS-Exploit preview

TP-Link-Archer-CR-700-XSS-Exploit

GitHubayushman4/tp-link-archer-cr-700-xss-exploit

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

exploitationiot-securitypenetration-testing+3
39 years ago
HTC preview

HTC

GitHubwmasday/htc

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

exploitationiot-securitypassword-attacks+3
33 years ago
XSS-CVE-2022-30489 preview

XSS-CVE-2022-30489

GitHubbadboycxcc/xss-cve-2022-30489

Proof-of-concept exploit for CVE-2022-30489, a stored XSS vulnerability in WAVLINK WN535G3 routers, demonstrating a POST-based attack via the…

exploitationiot-securitypenetration-testing+3
24 years ago
CVE-2021-35296 preview

CVE-2021-35296

GitHubafaq1337/cve-2021-35296

Proof-of-concept exploit for CVE-2021-35296 targeting PTCL Modem HG150-Ub, demonstrating a specific vulnerability for security testing and research.

exploitationiot-securitypenetration-testing+2
22 years ago
CVE-2024-55040-Sensaphone-XSS preview

CVE-2024-55040-Sensaphone-XSS

GitHubtcbutler320/cve-2024-55040-sensaphone-xss

Public disclose of several stored XSS vulnerabilities in the Sensaphone WEB600 (CVE-2024-55040)

exploitationiot-securitypenetration-testing+3
11 year ago
Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC preview

Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC

GitHubdarknesschieftain/injection-vulnerability-in-paradox-security-systems-ipr512-cve-2023-24709-poc

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

exploitationiot-securitypenetration-testing+3
3 years ago
boa-detector preview

boa-detector

GitHubcorelight/boa-detector

Zeek package for detecting the vulnerable Boa web server via HTTP Server header inspection. Raises a notice upon observation of vulnerable versions.

iot-securitynetwork-securitysupply-chain-security+3
3 years ago
CVE-2021-46108 preview

CVE-2021-46108

GitHubg-rubert/cve-2021-46108

Proof-of-concept for stored cross-site scripting (XSS) vulnerability in D-Link DSL-2730E routers via the username parameter on the maintenance…

exploitationiot-securitypenetration-testing+3
4 years ago
CVE-2020-14965 preview

CVE-2020-14965

GitHubg-rubert/cve-2020-14965

TP-LINK Multiple HTML Injection Vulnerabilities

embedded-systems-securityhardware-securityiot-security+3
5 years ago
Previous12Next