Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Code Analysis | Kitploit
Categories

Code Analysis

Static and dynamic code analysis, SAST, DAST, and code review tools.

Kitploit recommended

Top tools

10 selected
semgrep preview#1

semgrep

GitHubsemgrep/semgrep
16.2k5 days ago
codeql preview#2

codeql

GitHubgithub/codeql
10.1k2h 15m ago
sonarqube preview#3

sonarqube

GitHubsonarsource/sonarqube
11.0k21h 11m ago
infer preview#4

infer

GitHubfacebook/infer
15.7k6 days ago
ghidra preview#5

ghidra

GitHubnationalsecurityagency/ghidra
71.1k20h 51m ago
radare2 preview#6

radare2

GitHubradareorg/radare2
24.5k1 day ago
capa preview#7

capa

GitHubmandiant/capa
6.1k16 hours ago
bandit preview#8

bandit

GitHubpycqa/bandit
8.2k10 days ago
gosec preview#9

gosec

GitHubsecurego/gosec
8.9k2 days ago
bearer preview#10

bearer

GitHubbearer/bearer
2.7k16 days ago
NewestRelevanceMost popularRecently updated
2072 results
Sequelize-1day-CVE-2023-25813 preview

Sequelize-1day-CVE-2023-25813

GitHubbde574786/sequelize-1day-cve-2023-25813

Proof-of-concept and technical analysis of CVE-2023-25813, a SQL injection vulnerability in Sequelize ORM versions prior to 6.19.1, including…

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
XStream-1 preview

XStream-1

GitHubepicosy/xstream-1

Java library for XML serialization and deserialization, with a focus on CVE-2020-26217 exploitation. Enables converting Java objects to XML and back,…

static-analysisvulnerability-analysiscode-analysis+2
2 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubantunesmpedro/cve-2018-6574

CVE-2018-6574 go get

static-analysisvulnerability-analysiscode-analysis+2
3 years ago
CVE-2024-29399 preview

CVE-2024-29399

GitHubally-petitt/cve-2024-29399

CVE-2024-29399 reference

vulnerability-analysiscode-analysisexploitation+2
2 years ago
org.shaneking.demo.cve.y2021.s44228 preview

org.shaneking.demo.cve.y2021.s44228

GitHubshanekingblog/org.shaneking.demo.cve.y2021.s44228

CVE-2021-44228

static-analysisvulnerability-analysiscode-analysis+2
4 years ago
CVE-2022-0219 preview

CVE-2022-0219

GitHubhaxatron/cve-2022-0219

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

android-securitystatic-analysisvulnerability-analysis+3
4 years ago
CVE-2016-4463 preview

CVE-2016-4463

GitHubarntsonl/cve-2016-4463

Proof of concept for CVE-2016-4463

static-analysisvulnerability-analysiscode-analysis+2
8 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubinfosecjack/cve-2018-6574

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating directory traversal in Go's net/http package for security testing and…

vulnerability-analysiscode-analysisexploitation+2
6 years ago
CVE-2021-41078 preview

CVE-2021-41078

GitHubs-index/cve-2021-41078

nameko Arbitrary code execution due to YAML deserialization

payload-generationvulnerability-analysiscode-analysis+3
4 years ago
CVE-2020-25398 preview

CVE-2020-25398

GitHubh3llraiser/cve-2020-25398

CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.

vulnerability-analysiscode-analysisexploitation+2
5 years ago
Groovy-scripting-engine-CVE-2015-1427 preview

Groovy-scripting-engine-CVE-2015-1427

GitHubcyberharsh/groovy-scripting-engine-cve-2015-1427

Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

vulnerability-analysiscode-analysisexploitation+2
6 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubasavior2/cve-2018-6574

CVE-2018-6574 go get RCE

vulnerability-analysiscode-analysisexploitation+2
6 years ago
log4j-lookups-vulnerability preview

log4j-lookups-vulnerability

GitHubrenyuh/log4j-lookups-vulnerability

Log4j2 Vulnerability (CVE-2021-44228)

vulnerability-analysiscode-analysisexploitation+2
4 years ago
CVE-2024-57487-and-CVE-2024-57488 preview

CVE-2024-57487-and-CVE-2024-57488

GitHubaaryan-11-x/cve-2024-57487-and-cve-2024-57488

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

vulnerability-analysiscode-analysisexploitation+2
1 year ago
CVE-2024-56059 preview

CVE-2024-56059

GitHubrandomrobbiebf/cve-2024-56059

Partners <= 0.2.0 - Unauthenticated PHP Object Injection

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2024-10728 preview

CVE-2024-10728

GitHubrandomrobbiebf/cve-2024-10728

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

vulnerability-analysiscode-analysisexploitation+3
1 year ago
PoC-CVE-2025-3914-Aeropage-WordPress-File-Upload preview

PoC-CVE-2025-3914-Aeropage-WordPress-File-Upload

GitHublvl23ht/poc-cve-2025-3914-aeropage-wordpress-file-upload

CVE-2025-3914-PoC | The Aeropage Sync for Airtable WordPress plugin (≤ v3.2.0) is vulnerable to authenticated arbitrary file uploads due to…

payload-generationvulnerability-analysiscode-analysis+3
1 year ago
CVE-2025-22510 preview

CVE-2025-22510

GitHubdottak/cve-2025-22510

PoC of CVE-2025-22510

vulnerability-analysiscode-analysisexploitation+3
1 year ago
Previous1…99100Next