Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Identity & Access Management (IAM)

Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

Kitploit recommended

Top tools

10 selected
keycloak preview#1

keycloak

GitHubkeycloak/keycloak
36.7k9h 5m ago
authentik preview#2

authentik

GitHubgoauthentik/authentik
25.4k8h 56m ago
zitadel preview#3

zitadel

GitHubzitadel/zitadel
15.0k1 day ago
kratos preview#4

kratos

GitHubory/kratos
13.8k1 month ago
hydra preview#5

hydra

GitHubory/hydra
17.5k1 month ago
dex preview#6

dex

GitHubdexidp/dex
11.1k1 day ago
authelia preview#7

authelia

GitHubauthelia/authelia
28.5k13h 23m ago
kanidm preview#9

kanidm

GitHubkanidm/kanidm
5.4k1 day ago
freeipa preview#10

freeipa

GitHubfreeipa/freeipa
1.3k2 days ago
pomerium preview#11

pomerium

GitHubpomerium/pomerium
5.0k1h 50m ago
NewestRelevanceMost popularRecently updated
970 results
ff4j__ff4j_CVE-2022-44262_1-8-13 preview

ff4j__ff4j_CVE-2022-44262_1-8-13

GitHubshoucheng3/ff4j__ff4j_cve-2022-44262_1-8-13

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

authentication-authorizationgeneral-purpose-utilitiesscripting-automation+3
1 year ago
tugtainer-PoC preview

tugtainer-PoC

GitHubsqueeze440/tugtainer-poc

PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc-6vc7-xrfh, CVE-2026-87004, CVSS 8.1).

vulnerability-analysisexploitationweb-security+3
7 days ago
terrapod-PoC preview

terrapod-PoC

GitHubsqueeze440/terrapod-poc

PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

authentication-authorizationvulnerability-analysisexploitation+4
7 days ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubivanesk315/cve-2026-18963

Docker-based lab and Python exploit for CVE-2026-18963, a Keycloak reset-credentials flow bypass enabling account takeover via email verification…

vulnerability-analysisexploitationweb-application-exploitation+6
15h 39m ago
CVE-2026-76578 preview

CVE-2026-76578

GitHubbrainbob/cve-2026-76578

Proof-of-concept exploit for CVE-2026-76578 and CVE-2026-76560, chaining anonymous LDAP ADD with a 389-ds SELFDN bypass to gain FreeIPA domain admin…

identity-managementvulnerability-analysisexploitation+5
1 day ago
cve-2026-41940-PoC-Linux preview

cve-2026-41940-PoC-Linux

GitHubxrzmodz444/cve-2026-41940-poc-linux

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports custom payloads and verbose logging, compatible with…

authentication-authorizationvulnerability-analysisexploitation+2
1 day ago
TATS preview

TATS

GitHubicemoonhsv/tats

Analyze and track OAuth 2.0, OIDC, and Microsoft Entra ID tokens from Burp, mitmproxy, or Chrome DevTools captures. Visualize token lifecycles,…

web-securitypenetration-testingidentity-access-management+2
716 days ago
CVE-2026-73318 preview

CVE-2026-73318

GitHubbombobombone/cve-2026-73318

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…

authentication-authorizationvulnerability-analysisexploitation+3
2 days ago
CVE-2026-73317 preview

CVE-2026-73317

GitHubbombobombone/cve-2026-73317

Proof-of-concept exploit and technical write-up for CVE-2026-73317, an authorization bypass in XenForo allowing limited admins to approve content as…

authentication-authorizationvulnerability-analysisexploitation+3
2 days ago
CVE-2026-73309 preview

CVE-2026-73309

GitHubbombobombone/cve-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

authentication-authorizationvulnerability-analysisexploitation+2
2 days ago
hdwebmobile-booking-appointments preview

hdwebmobile-booking-appointments

GitHubhtrxuan/hdwebmobile-booking-appointments

Sell bookable services and appointments through WooCommerce -- closes CVE-2026-2931 by construction.

authentication-authorizationvulnerability-analysisweb-security+2
2 days ago
security-baseline-ubuntu preview

security-baseline-ubuntu

GitHubeugexo/security-baseline-ubuntu

Production-grade Security Baseline & Hardening Guide for Ubuntu 24.04/26.04 LTS. Kernel isolation, custom AppArmor/Firejail 0.9.80, Rootless Docker,…

vulnerability-scannersencryption-decryption-toolsconfiguration-auditing+6
114 days ago
CVE-2026-82329-JFrog-Artifactory- preview

CVE-2026-82329-JFrog-Artifactory-

GitHub0xterror/cve-2026-82329-jfrog-artifactory-

Exploit PoC for CVE-2026-82329, an authentication bypass in JFrog Artifactory. Demonstrates forging JWT tokens to gain admin access and create a…

authentication-authorizationvulnerability-analysisexploitation+2
3 days ago
pigeon preview

pigeon

GitHubpigeonlabshq/pigeon

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

authentication-authorizationcloud-securitydevsecops+3
74 days ago
CVE-2026-41940 preview

CVE-2026-41940

GitHub0xgh057r3c0n/cve-2026-41940

cPanel & WHM - Authentication Bypass via Session-File CRLF Injection

authentication-authorizationvulnerability-scannersexploitation+4
15 days ago
CVE-2026-82329 preview

CVE-2026-82329

GitHub0xcyp1337/cve-2026-82329

Mass exploit for CVE-2026-82329, an unauthenticated authentication bypass in JFrog Artifactory. Supports single-target and batch scanning with…

authentication-authorizationvulnerability-scannersexploitation+3
7 days ago
synapse preview
Archived

synapse

GitHubmatrix-org/synapse

Synapse: Matrix homeserver written in Python/Twisted.

authentication-authorizationencryption-decryption-toolsnetwork-security+3
12.1k2 years ago
unshackle preview
Archived

unshackle

GitHubfadi002/unshackle

Open-source tool to bypass windows and linux passwords from bootable usb

authentication-authorizationprivilege-escalationpassword-attacks+3
2.0k2 years ago
Previous1…525354Next