Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Code Analysis

Static and dynamic code analysis, SAST, DAST, and code review tools.

Kitploit recommended

Top tools

10 selected
semgrep preview#1

semgrep

GitHubsemgrep/semgrep
16.2k6 days ago
codeql preview#2

codeql

GitHubgithub/codeql
10.1k1h 55m ago
sonarqube preview#3

sonarqube

GitHubsonarsource/sonarqube
11.0k22h 55m ago
infer preview#4

infer

GitHubfacebook/infer
15.7k1 day ago
ghidra preview#5

ghidra

GitHubnationalsecurityagency/ghidra
71.1k1 day ago
radare2 preview#6

radare2

GitHubradareorg/radare2
24.5k2 days ago
capa preview#7

capa

GitHubmandiant/capa
6.1k1 day ago
bandit preview#8

bandit

GitHubpycqa/bandit
8.2k11 days ago
gosec preview#9

gosec

GitHubsecurego/gosec
8.9k3 days ago
bearer preview#10

bearer

GitHubbearer/bearer
2.7k17 days ago
NewestRelevanceMost popularRecently updated
2074 results
ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-24891_2-2-3-1

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

authentication-authorizationstatic-analysisencryption-decryption-tools+5
1 year ago
rsyslog-librelp-CVE-2018-1000140-fixed preview

rsyslog-librelp-CVE-2018-1000140-fixed

GitHubs0/rsyslog-librelp-cve-2018-1000140-fixed

Patch for CVE-2018-1000140 in rsyslog's librelp library, fixing a remote code execution vulnerability in the reliable event logging protocol…

vulnerability-analysiscode-analysisexploitation+2
7 years ago
rust-cve-2025-55182 preview

rust-cve-2025-55182

GitHubfaizdotid/rust-cve-2025-55182

Exploit tool for CVE-2025-55182, providing targeted vulnerability testing and exploitation capabilities for security assessments.

vulnerability-analysiscode-analysisexploitation+2
8 months ago
CVE-2025-50361 preview

CVE-2025-50361

GitHubch1keen/cve-2025-50361

Report and PoC of Global Buffer Overflow on SmallBASIC before 02364eff880ba62afac67bcceebafade2b40d21f

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
Jenkins-CVE-2015-8103 preview

Jenkins-CVE-2015-8103

GitHubr00t4dm/jenkins-cve-2015-8103

Exploit for Jenkins CVE-2015-8103, a remote code execution vulnerability in the Jenkins CLI. Enables authenticated attackers to execute arbitrary…

vulnerability-analysiscode-analysisexploitation+2
3 years ago
CVE-2024-28397-js2py-Sandbox-Escape preview

CVE-2024-28397-js2py-Sandbox-Escape

GitHubnaved124/cve-2024-28397-js2py-sandbox-escape

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…

vulnerability-analysiscode-analysisexploitation+5
1 year ago
tough-cookie-2.5.0-cve-2023-26136-fix preview

tough-cookie-2.5.0-cve-2023-26136-fix

GitHuburiyahav/tough-cookie-2.5.0-cve-2023-26136-fix

ecurity patch for CVE-2023-26136 in tough-cookie 2.5.0 - Prototype pollution vulnerability fix with backward compatibility

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
jeremylong__DependencyCheck_CVE-2018-12036_3-1-2 preview

jeremylong__DependencyCheck_CVE-2018-12036_3-1-2

GitHubshoucheng3/jeremylong__dependencycheck_cve-2018-12036_3-1-2

Software composition analysis tool that detects publicly disclosed vulnerabilities in project dependencies using CPE matching, generating detailed…

static-analysisvulnerability-scannersvulnerability-analysis+3
1 year ago
actions-secrets preview

actions-secrets

GitHubgmh5225/actions-secrets

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

static-code-analysiscode-analysisdevsecops+1
3 years ago
unicode-control-characters-action preview

unicode-control-characters-action

GitHubpierdipi/unicode-control-characters-action

A GitHub Action to find Unicode control characters using the Red Hat diagnostic tool https://access.redhat.com/security/vulnerabilities/RHSB-2021-007…

static-analysisvulnerability-analysiscode-analysis+3
3 years ago
log4shell-example preview

log4shell-example

GitHubchilit-nl/log4shell-example

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

vulnerability-analysiscode-analysisexploitation+3
4 years ago
CVE-2020-26258 preview

CVE-2020-26258

GitHubal1ex/cve-2020-26258

CVE-2020-26258 && XStream SSRF

vulnerability-analysiscode-analysisexploitation+2
5 years ago
tinyxml preview

tinyxml

GitHubvm2mv/tinyxml

TinyXML 2.6.2 with fixes for CVE-2021-42260 and CVE-2023-34194

general-purpose-utilitiesstatic-analysiscode-analysis+1
11 year ago
Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Code-Execution preview

Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Code-Execution

GitHubsanupl/vehicle-service-management-system-multiple-file-upload-leads-to-code-execution

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

payload-generationvulnerability-analysiscode-analysis+3
4 months ago
cve-2026-33937 preview

cve-2026-33937

GitHubdinhvaren/cve-2026-33937

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

vulnerability-analysiscode-analysisexploitation+2
4 months ago
zip4j preview

zip4j

GitHubiris-sast/zip4j

CWE-Bench-Java CVE-2018-1002202 versions 1.3.2, 1.3.3

static-analysisvulnerability-analysiscode-analysis+2
1 year ago
external_expat_2.1.0_CVE-2022-43680 preview

external_expat_2.1.0_CVE-2022-43680

GitHubnidhihcl/external_expat_2.1.0_cve-2022-43680

C library for stream-oriented XML parsing with a focus on vulnerability analysis and exploitation of CVE-2022-43680, enabling fuzzing and…

static-analysisvulnerability-analysiscode-analysis+3
3 years ago
apache-commons-lang2 preview

apache-commons-lang2

GitHubnjawalkar/apache-commons-lang2

Apache's commons-lang2 v2.6 with a backported fix for CVE-2025-48924

general-purpose-utilitiesvulnerability-analysiscode-analysis+1
10 months ago
Previous1…868788…100Next