#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

jquery file upload poc

OpenSSL 1.1.0g cryptographic library and TLS toolkit, providing encryption, decryption, certificate management, and SSL/TLS protocol support for…

Java library for fast, configurable cleansing of untrusted HTML to prevent cross-site scripting (XSS) attacks. Uses policy-driven scanning to…

Sentinel demo: transitive snakeyaml CVE-2022-1471 via Spring Boot + exploitable code pattern

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…


Anticipator is an open-source threat detection platform for multi-agent AI systems.

Java library providing technical commons for XWiki projects, with a focus on vulnerability analysis and static code inspection for security testing.

Java utility library with a focus on a specific CVE vulnerability, providing code analysis and static analysis capabilities for security assessment.

Exploit code for CVE-2023-40127, a vulnerability in Android. Provides proof-of-concept implementation for security research and testing.

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…

Reference implementation of Bean Validation 2.0 (JSR-380) with annotation-based metadata model and method validation for JavaBeans, including a…

Technical Java libraries providing common utilities and components for the XWiki platform, including security vulnerability fixes and code analysis…


CodeQL query test for CVE-2023-24329, demonstrating static analysis detection of a specific vulnerability in Python's urllib.parse module.

Exploit module for Apache JSPWiki CVE-2019-10078, enabling security testing of Java-based wiki platforms through targeted vulnerability exploitation…

C-based detection tool for CVE-2017-2793, enabling identification and analysis of the specific vulnerability in affected systems.