Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Code Analysis | Kitploit
Categories

Code Analysis

Static and dynamic code analysis, SAST, DAST, and code review tools.

Kitploit recommended

Top tools

10 selected
semgrep preview#1

semgrep

GitHubsemgrep/semgrep
16.2k6 days ago
codeql preview#2

codeql

GitHubgithub/codeql
10.1k22h 18m ago
sonarqube preview#3

sonarqube

GitHubsonarsource/sonarqube
11.0k20h 34m ago
infer preview#4

infer

GitHubfacebook/infer
15.7k1 day ago
ghidra preview#5

ghidra

GitHubnationalsecurityagency/ghidra
71.1k1 day ago
radare2 preview#6

radare2

GitHubradareorg/radare2
24.5k2 days ago
capa preview#7

capa

GitHubmandiant/capa
6.1k1 day ago
bandit preview#8

bandit

GitHubpycqa/bandit
8.2k11 days ago
gosec preview#9

gosec

GitHubsecurego/gosec
8.9k3 days ago
bearer preview#10

bearer

GitHubbearer/bearer
2.7k17 days ago
NewestRelevanceMost popularRecently updated
2074 results
CVE-2026-23885 preview

CVE-2026-23885

GitHubthedeepopc/cve-2026-23885

Proof-of-concept exploit for CVE-2026-23885, an authenticated RCE in AlchemyCMS via eval() injection, with technical analysis and remediation…

vulnerability-analysiscode-analysisexploitation+2
7 months ago
webp_Android10_r33_CVE-2023-1999 preview

webp_Android10_r33_CVE-2023-1999

GitHubpazhanivelmani/webp_android10_r33_cve-2023-1999

Proof-of-concept exploit for CVE-2023-1999 targeting the WebP codec library on Android 10 (r33). Demonstrates a heap buffer overflow vulnerability in…

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
Confluence-CVE-2021-26084 preview

Confluence-CVE-2021-26084

GitHub30579096/confluence-cve-2021-26084

OGNL Injection in Confluence server version < 7.12.5

vulnerability-analysiscode-analysisexploitation+2
5 years ago
magento2-template-filter-patch preview

magento2-template-filter-patch

GitHubwubinworks/magento2-template-filter-patch

Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
packages_apps_Settings_AOSP10_r33_CVE-2021-0506 preview

packages_apps_Settings_AOSP10_r33_CVE-2021-0506

GitHubsatheesh575555/packages_apps_settings_aosp10_r33_cve-2021-0506
android-securityvulnerability-analysiscode-analysis+2
4 years ago
CVE-2025-59059-Misattributed-RCE-in-Apache-Ranger-Static-Analysis-Correction preview

CVE-2025-59059-Misattributed-RCE-in-Apache-Ranger-Static-Analysis-Correction

GitHubpl4tyz/cve-2025-59059-misattributed-rce-in-apache-ranger-static-analysis-correction

CVE-2025-59059: Misattributed RCE in Apache Ranger Static Analysis Correction

static-analysisvulnerability-analysiscode-analysis+3
5 months ago
CVE-2020-10673 preview

CVE-2020-10673

GitHubharry1080/cve-2020-10673

CVE-2020-10673

static-analysisvulnerability-analysiscode-analysis+2
6 years ago
asf__tapestry-5_CVE-2019-0207_5-4-4 preview

asf__tapestry-5_CVE-2019-0207_5-4-4

GitHubshoucheng3/asf__tapestry-5_cve-2019-0207_5-4-4

Proof-of-concept exploit for CVE-2019-0207 in Apache Tapestry 5.4.4, demonstrating remote code execution via deserialization vulnerability.

vulnerability-analysiscode-analysisexploitation+2
1 year ago
cve-2025-32756 preview

cve-2025-32756

GitHubshan0ar/cve-2025-32756

Proof-of-concept exploit for CVE-2025-32756, demonstrating the vulnerability and providing a basis for security testing and remediation validation.

vulnerability-analysiscode-analysisexploitation+2
1 year ago
CVE-2013-3900 preview

CVE-2013-3900

GitHubsabecomoeh/cve-2013-3900

Proof-of-concept exploit for CVE-2013-3900, a WinVerifyTrust signature validation vulnerability enabling arbitrary code execution via crafted…

vulnerability-analysiscode-analysisexploitation+1
1 year ago
CVE-2013-0156 preview

CVE-2013-0156

GitHubr3dkn33-zz/cve-2013-0156

Arbitrary deserialization that can be used to trigger SQL injection and even Code execution

vulnerability-analysiscode-analysisexploitation+2
7 years ago
batchOverflow preview

batchOverflow

GitHubphzietsman/batchoverflow

A fix for the batchOverflow bug https://medium.com/@peckshield/alert-new-batchoverflow-bug-in-multiple-erc20-smart-contracts-cve-2018-10299-511067db65…

static-analysisvulnerability-analysiscode-analysis+1
8 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubseoqqq/cve-2018-6574

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

vulnerability-analysiscode-analysisexploitation+2
3 years ago
CVE-2024-42461 preview

CVE-2024-42461

GitHubfevar54/cve-2024-42461

Fix for ECDSA and EDDSA signature verification in Wycheproof project, addressing missing length checks that allowed zero-byte manipulation during…

static-analysisencryption-decryption-toolsvulnerability-analysis+2
2 years ago
CurveballCertTool preview

CurveballCertTool

GitHubcrackercat/curveballcerttool

PoC for CVE-2020-0601 vulnerability (Code Signing)

vulnerability-analysiscode-analysisexploitation+3
6 years ago
external_expat_AOSP10_r33_CVE-2022-22822toCVE-2022-22827 preview

external_expat_AOSP10_r33_CVE-2022-22822toCVE-2022-22827

GitHubnanopathi/external_expat_aosp10_r33_cve-2022-22822tocve-2022-22827

Patched version of the Expat XML parser library addressing multiple CVEs (CVE-2022-22822 through CVE-2022-22827) for AOSP 10 r33, providing…

general-purpose-utilitiesstatic-analysisvulnerability-analysis+2
3 years ago
srikanth-lingala__zip4j_CVE-2018-1002202_1-3-2 preview

srikanth-lingala__zip4j_CVE-2018-1002202_1-3-2

GitHubshoucheng3/srikanth-lingala__zip4j_cve-2018-1002202_1-3-2

Decompiled source code of zip4j library versions 1.3.2 (vulnerable) and 1.3.3 (fixed) for CVE-2018-1002202 path traversal analysis, part of the…

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
apache__sling-org-apache-sling-xss_CVE-2016-5394_1-0-8 preview

apache__sling-org-apache-sling-xss_CVE-2016-5394_1-0-8

GitHubshoucheng3/apache__sling-org-apache-sling-xss_cve-2016-5394_1-0-8

Java library providing XSS escaping and filtering services (XSSAPI, XSSFilter) to sanitize user-submitted content and prevent cross-site scripting…

static-analysisvulnerability-analysiscode-analysis+2
1 year ago
Previous1…888990…100Next