#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

C library for parsing XML, specifically patched for CVE-2022-23990, providing a reference implementation for vulnerability analysis and secure coding…

OpenSSL toolkit providing TLS/SSL protocols and general-purpose cryptographic library with command-line tools for key generation, certificate…

VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection

Public disclosure for CVE-2023-31584.

Android framework patch for CVE-2023-21284, addressing a security vulnerability in AOSP 10.

Android platform framework repository containing a patch or analysis for CVE-2023-21288, a vulnerability in the Android framework.

Android AAC codec vulnerability analysis and patch for CVE-2022-20130, focusing on memory corruption in external AAC library.

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Web services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, WS-Trust, and JAX-WS/JAX-RS APIs.

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

Grails sample application using the Javamelody 1.44 plugin to illustrate the CVE-2013-4378 vulnerability.

Android MediaProvider vulnerability analysis and patch for CVE-2023-40127, focusing on security assessment and remediation.

Android netd vulnerability analysis and exploitation research for CVE-2023-40084, focusing on the platform's network daemon.

Analyzes and patches a specific Android vulnerability (CVE-2023-21282) in the AAC audio codec, providing a patched AOSP10 source tree for security…

OpenSSL 1.0.1g source code with CVE-2015-1791 patch, providing SSL/TLS and cryptographic library for secure communications.

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

Fork spring-webmvc 5.3.39 to fix CVE-2024-38816, CVE-2024-38819