#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

Patch for CVE-2018-1000140 in rsyslog's librelp library, fixing a remote code execution vulnerability in the reliable event logging protocol…

Exploit tool for CVE-2025-55182, providing targeted vulnerability testing and exploitation capabilities for security assessments.

Report and PoC of Global Buffer Overflow on SmallBASIC before 02364eff880ba62afac67bcceebafade2b40d21f

Exploit for Jenkins CVE-2015-8103, a remote code execution vulnerability in the Jenkins CLI. Enables authenticated attackers to execute arbitrary…

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…

ecurity patch for CVE-2023-26136 in tough-cookie 2.5.0 - Prototype pollution vulnerability fix with backward compatibility

Software composition analysis tool that detects publicly disclosed vulnerabilities in project dependencies using CPE matching, generating detailed…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

A GitHub Action to find Unicode control characters using the Red Hat diagnostic tool https://access.redhat.com/security/vulnerabilities/RHSB-2021-007…

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

CVE-2020-26258 && XStream SSRF

TinyXML 2.6.2 with fixes for CVE-2021-42260 and CVE-2023-34194

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

CWE-Bench-Java CVE-2018-1002202 versions 1.3.2, 1.3.3

C library for stream-oriented XML parsing with a focus on vulnerability analysis and exploitation of CVE-2022-43680, enabling fuzzing and…

Apache's commons-lang2 v2.6 with a backported fix for CVE-2025-48924