Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Identity & Access Management (IAM)

Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

NewestRelevanceMost popularRecently updated
878 results
CVE-2026-16232 preview

CVE-2026-16232

GitHubhackspeak/cve-2026-16232

CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

authentication-authorizationvulnerability-analysisexploitation+1
2
17 days ago
awesome-entra preview

awesome-entra

GitHubmerill/awesome-entra

😎 Awesome list of all things related to Microsoft Entra

authentication-authorizationconfiguration-auditingpenetration-testing+5
7712 months ago
santa preview

santa

GitHubnorthpolesec/santa

A binary and file access authorization system for macOS.

authentication-authorizationdefensive-toolsbinary-analysis+2
7223 days ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection
authentication-authorizationexploitationweb-application-exploitation+4
18 days ago
nextjs-middleware-auth-bypass-lab preview

nextjs-middleware-auth-bypass-lab

GitHubberraesen/nextjs-middleware-auth-bypass-lab

Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

authentication-authorizationweb-application-exploitationweb-security+3
118 days ago
OpenSC.tokend preview

OpenSC.tokend

GitHubopensc/opensc.tokend

Tokend module for OS X with support for all cards supported by OpenSC

cryptographyhardware-securityidentity-access-management+1
362 years ago
OpenSC preview

OpenSC

GitHubx41sec/opensc

OpenSC bugfixing

encryption-decryption-toolscryptographyhardware-security+2
18 years ago
pam_pkcs11 preview

pam_pkcs11

GitHubx41sec/pam_pkcs11

pam_pkcs11 Bugfix

authentication-authorizationcryptographyhardware-security+2
28 years ago
CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover- preview

CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover-

GitHubgeorge0papasotiriou/cve-2026-3456-oauth2-pkce-race-condition-account-takeover-
authentication-authorizationvulnerability-analysisexploitation+3
18 days ago
Kangaroo preview

Kangaroo

GitHubmonkeysec-sys/kangaroo

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

authentication-authorizationvulnerability-analysisexploitation+3
218 days ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubkill1234545/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authentication-authorizationprivilege-escalationpersistence-mechanisms+5
103 months ago
CVE-2026-15964-PoC preview

CVE-2026-15964-PoC

GitHubinstructor-admin/cve-2026-15964-poc

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

authentication-authorizationprivilege-escalationweb-vulnerability-scanners+5
119 days ago
CVE-2026-58424 preview

CVE-2026-58424

GitHubbridgeralderson/cve-2026-58424

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

authentication-authorizationvulnerability-analysisexploitation+4
219 days ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubvanhari/cve-2026-39987

Proof-of-concept exploit for an authentication bypass in marimo's terminal WebSocket endpoint, enabling unauthenticated command execution in versions…

authentication-authorizationvulnerability-analysisexploitation+3
18 days ago
CVE-2026-53625-GLPI-PoC preview

CVE-2026-53625-GLPI-PoC

GitHub7h30th3r0n3/cve-2026-53625-glpi-poc

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

authentication-authorizationprivilege-escalationexploitation+4
20 days ago
CVE-2026-53576 preview

CVE-2026-53576

GitHubtamatahyt/cve-2026-53576

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

authentication-authorizationprivilege-escalationexploitation+7
20 days ago
CVE-2026-8239 preview

CVE-2026-8239

GitHubaj2108/cve-2026-8239

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

authentication-authorizationvulnerability-analysisweb-application-exploitation+3
20 days ago
CVE-2026-8237 preview

CVE-2026-8237

GitHubaj2108/cve-2026-8237

In-depth IDOR write-up for Concrete CMS, covering the message_detail endpoint, missing authorization root cause, attack scenarios, impact, and fix.

authentication-authorizationvulnerability-analysisweb-application-exploitation+2
20 days ago
Previous1…567…49Next