#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

Proof-of-concept and technical analysis of CVE-2023-25813, a SQL injection vulnerability in Sequelize ORM versions prior to 6.19.1, including…
Java library for XML serialization and deserialization, with a focus on CVE-2020-26217 exploitation. Enables converting Java objects to XML and back,…

CVE-2018-6574 go get

CVE-2024-29399 reference

CVE-2021-44228

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

Proof of concept for CVE-2016-4463

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating directory traversal in Go's net/http package for security testing and…

nameko Arbitrary code execution due to YAML deserialization

CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.

Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

CVE-2018-6574 go get RCE

Log4j2 Vulnerability (CVE-2021-44228)

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

Partners <= 0.2.0 - Unauthenticated PHP Object Injection

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

CVE-2025-3914-PoC | The Aeropage Sync for Airtable WordPress plugin (≤ v3.2.0) is vulnerable to authenticated arbitrary file uploads due to…

PoC of CVE-2025-22510