Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PoC-in-GitHub — 📡 PoC auto collect from GitHub. ⚠️ Be careful Malware. | Kitploit
Tools/GitHubGitHub/nomi-sec/poc-in-github
OSINT (Open Source Intelligence)Vulnerability ScannersVulnerability AnalysisExploitationInformation GatheringPenetration TestingThreat IntelligencePapers & ResearchRed TeamingCurated Resources
GitHub
8.0k1.3k1014 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
nomi-sec/poc-in-github

PoC-in-GitHub

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

View RepositoryWebsite

PoC in GitHub

2026

CVE-2026-0006 (2026-03-02)

In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • mobilehackinglab/CVE-2026-0006-openapv-poc

CVE-2026-0009 (2026-06-01)

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • cduram/NotCVE-2026-0009

CVE-2026-0010 (2026-03-02)

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • cduram/NotCVE-2026-0010

CVE-2026-0013 (2026-03-02)

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • inforcqb/cve-2026-0013-exploit
  • XiaoBaiLovesStirring/cve-2026-0013-poc

CVE-2026-0014 (2026-03-02)

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • cduram/NotCVE-2026-0014

CVE-2026-0023 (2026-03-02)

In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • QM4RS/CVE-2026-0023-Update-Ownership-PoC

CVE-2026-0047 (2026-03-02)

In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • mobilehackinglab/CVE-2026-0047-poc

CVE-2026-0049 (2026-04-06)

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • R3n3r0/CVE-2026-0049

CVE-2026-0073 (2026-05-04)

In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.

  • novaek/CVE-2026-0073-Research
  • SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC
  • devtint/CVE-2026-0073
  • adityatelange/poc-CVE-2026-0073
  • MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC
  • unnaim/adbHijacker
  • 0xBlackash/CVE-2026-0073
  • xqi1337/poc-CVE-2026-0073
  • tc4dy/CVE-2026-0073-PoC-Exploit
  • 0xbinder/CVE-2026-0073
  • m00ddy/CVE-2026-0073-Android-client-TLS-auth-bypass
  • fredevsec/CVE-2026-0073
  • ctn-Qvo/CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN
  • aye468448-eng/CVE-2026-0073-Android-adbd-authentication-bypass
  • naheeju/POC-CVE-2026-0073

CVE-2026-0075 (2026-06-01)

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • QM4RS/CVE-2026-0075

CVE-2026-0091 (2026-06-01)

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • canyie/TransitionPlayer

CVE-2026-0092 (2026-06-17)

In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • Majorjayyy1/CVE-2026-0092

CVE-2026-0101

  • George0Papasotiriou/CVE-2026-0101-BLE-Address-Spoofing-via-Weak-Resolvable-Private-Address

CVE-2026-01443

  • gduma-phData/patch-CVE-2026-01443

CVE-2026-0163 (2026-08-04)

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • sentinel-aidefense/CVE-2026-0163-EXP

CVE-2026-0257 (2026-05-13)

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.\n\nPanorama and Cloud NGFW are not impacted by these issues.

  • sfewer-r7/CVE-2026-0257
  • akashsingh0454/CVE-2026-0257-PoC
  • HORKimhab/CVE-2026-0257
  • 0xBlackash/CVE-2026-0257
  • tushargurav28/CVE-2026-0257
  • grayxploit/CVE-2026-0257
  • Ez4rd1x1/CVE-2026-0257

CVE-2026-0265 (2026-05-13)

Download Tool