#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

一个由AI生成的漏洞验证应用


Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Demo of CVE-2020-9488: Unsafe logging with Log4j and remediation

Arguments to reject CVE-2025-56005

Checks projects for compromised packages, suspicious files, and import statements.

C library for parsing, editing, and saving EXIF metadata, with a focus on addressing CVE-2020-0198 in AOSP10.

Java XML serialization library with a focus on the CVE-2013-7285 deserialization vulnerability, providing source code, binaries, and documentation…

Analysis and exploitation code for CVE-2024-23673, a vulnerability in Apache Sling Servlet Resolver, enabling targeted security testing of…

yasa

Proof-of-concept exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Includes Dockerfile for reproducible testing…

Proof-of-concept exploit for CVE-2018-10546: crafted data triggers infinite loop via PHP stream filter 'convert.iconv.*', causing CPU exhaustion in…

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing…

Introduction to CVE-2023-6933 Vulnerability

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)

Remote code execution exploit for CVE-2019-11043 targeting Nginx with php-fpm. Includes Go and pre-compiled exploit binaries for testing vulnerable…