#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

Proof-of-concept exploit for CVE-2019-5413, a remote code execution vulnerability in Apache NetBeans. Demonstrates exploitation via crafted XML…

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Proof-of-concept for CVE-2025-52099, an integer overflow in SQLite 3.50.0's setupLookaside function leading to heap-buffer-overflow.

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Proof-of-concept exploit for CVE-2019-5413 targeting NetBeans IDE, demonstrating remote code execution via crafted project files.

This repository contains a solution for the CVE-2023-26136 vulnerability.

cve-2018-6574 @pentesterlab

Demonstration of CVE-2022-42889 (Text4Shell) remote code execution vulnerability in Apache Commons Text with a proof-of-concept exploit.

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545

CVE-2018-6574

Exploit code and analysis for CVE-2023-26049 targeting Jetty 9.4.31, demonstrating a vulnerability in the web server for security testing and…

Exploit for CVE-2025-28915: WordPress ThemeEgg ToolKit arbitrary file upload vulnerability allowing remote Web Shell deployment. Includes…

Laravel debug mode - Remote Code Execution (RCE)

glibc getaddrinfo stack-based buffer overflow

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…