#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

Analyzes and demonstrates the Android Runtime vulnerability CVE-2021-0394, providing code-level insights for security researchers and developers.
Analyzes and patches Android AAC (Adaptive Audio Coding) library for CVE-2023-21282, focusing on vulnerability assessment and code-level fixes.

Remote code execution in Mediawiki Score

Proof-of-concept for CVE-2024-43018: SQL injection in Piwigo 13.8.0 via unsanitized max_level and min_register parameters, enabling information…


Exploit for CVE-2022-25175 targeting Jenkins Pipeline: Multibranch plugin, enabling automated exploitation of a specific vulnerability in CI/CD…

Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command. Demonstrates exploitation via malicious…

CVE-2022-30929 POC

OpenSSL toolkit providing TLS/SSL protocols and general-purpose cryptographic library with command-line tools for key generation, certificate…

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to…

version between CVE-2018-20433 and CVE-2019-5427


OpenSSL 1.1.1g source snapshot, a robust TLS/SSL and general-purpose cryptographic library with command-line tools for key generation, certificate…

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Exploit code for CVE-2023-40127, a vulnerability in Android MediaProvider, demonstrating the flaw for security research and testing.

Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)

Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228