Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Code Analysis | Kitploit
Categories

Code Analysis

Static and dynamic code analysis, SAST, DAST, and code review tools.

Kitploit recommended

Top tools

10 selected
semgrep preview#1

semgrep

GitHubsemgrep/semgrep
16.2k5 days ago
codeql preview#2

codeql

GitHubgithub/codeql
10.1k4h 51m ago
sonarqube preview#3

sonarqube

GitHubsonarsource/sonarqube
11.0k0 days ago
infer preview#4

infer

GitHubfacebook/infer
15.7k6 days ago
ghidra preview#5

ghidra

GitHubnationalsecurityagency/ghidra
71.1k0 days ago
radare2 preview#6

radare2

GitHubradareorg/radare2
24.5k1 day ago
capa preview#7

capa

GitHubmandiant/capa
6.1k18h 35m ago
bandit preview#8

bandit

GitHubpycqa/bandit
8.2k11 days ago
gosec preview#9

gosec

GitHubsecurego/gosec
8.9k2 days ago
bearer preview#10

bearer

GitHubbearer/bearer
2.7k16 days ago
NewestRelevanceMost popularRecently updated
2073 results
external_expat_AOSP10_r33_CVE-2022-25236 preview

external_expat_AOSP10_r33_CVE-2022-25236

GitHubsatheesh575555/external_expat_aosp10_r33_cve-2022-25236

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

static-analysisvulnerability-analysiscode-analysis+3
4 years ago
duo-agentflow-auditor preview

duo-agentflow-auditor

GitLabcentisgood/duo-agentflow-auditor

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

static-analysisvulnerability-scannerscode-analysis+8
6 months ago
Reproduce-CVE-2024-21513 preview

Reproduce-CVE-2024-21513

GitHubsavagesanta11/reproduce-cve-2024-21513

Demonstrates CVE-2024-21513 in langchain-experimental, showing arbitrary code execution via VectorSQLDatabaseChain's eval() on retrieved values.…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
GHSA-4cx5-89vm-833x-POC preview

GHSA-4cx5-89vm-833x-POC

GitHubjacklosingheart/ghsa-4cx5-89vm-833x-poc

GHSA-4cx5-89vm-833x/CVE-2024-52800

vulnerability-analysiscode-analysisexploitation+2
1 year ago
apache-struts-cve-2017-9805 preview

apache-struts-cve-2017-9805

GitHubrvermeulen/apache-struts-cve-2017-9805

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

vulnerability-analysiscode-analysisexploitation+3
5 years ago
CVE-2018-8032 preview

CVE-2018-8032

GitHubcairuojin/cve-2018-8032

从老外那里下载了该漏洞的修复工程,无奈依赖包实在是太多下不下来,选取其中axis工程打成jar包后发现已成功修复项目的漏洞,有需要的亲可以下载重新打jar包替换即可。 clone后用idea打axis这个jar包即可

vulnerability-analysiscode-analysisweb-security+2
3 years ago
CVE-2017-9841 preview

CVE-2017-9841

GitHubmbrasile/cve-2017-9841

CVE-2017-9841 detector script

static-analysisvulnerability-scannersvulnerability-analysis+3
6 years ago
CVE-2024-12877 preview

CVE-2024-12877

GitHubrandomrobbiebf/cve-2024-12877

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

payload-generationvulnerability-analysiscode-analysis+4
1 year ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubnsbyte/cve-2018-6574

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating remote code execution via crafted requests to vulnerable Go applications.

vulnerability-analysiscode-analysisexploitation+2
3 years ago
CVE-2024-10410 preview

CVE-2024-10410

GitHubk1nakoo/cve-2024-10410

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

payload-generationvulnerability-analysiscode-analysis+3
1 year ago
CVE-2016-2098 preview

CVE-2016-2098

GitHubdebalinax64/cve-2016-2098

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

vulnerability-analysiscode-analysisexploitation+2
5 years ago
CVE-2017-7504-poc preview

CVE-2017-7504-poc

GitHubwudidwo/cve-2017-7504-poc

Proof-of-concept exploit for CVE-2017-7504 targeting JBoss 4.x JBossMQ JMS deserialization vulnerability. Includes usage help via -h flag.

payload-generationvulnerability-analysiscode-analysis+3
1 year ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubjack0we/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387, a remote code execution vulnerability in OpenSSH server, demonstrating exploitation techniques for…

vulnerability-scannerscode-analysisexploitation+2
2 years ago
CVE-2024-6330 preview

CVE-2024-6330

GitHubrandomrobbiebf/cve-2024-6330

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2024-28397-js2py-Sandbox-Escape preview

CVE-2024-28397-js2py-Sandbox-Escape

GitHubcyber-warrior-sec/cve-2024-28397-js2py-sandbox-escape

Proof-of-concept exploit for CVE-2024-28397, a sandbox escape in js2py allowing remote code execution via crafted JavaScript, with a dynamic patch…

vulnerability-analysiscode-analysisexploitation+3
2 years ago
jenkinsci__script-security-plugin_CVE-2023-24422_1228.vd93135a_2fb_25 preview

jenkinsci__script-security-plugin_CVE-2023-24422_1228.vd93135a_2fb_25

GitHubshoucheng3/jenkinsci__script-security-plugin_cve-2023-24422_1228.vd93135a_2fb_25

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

authentication-authorizationstatic-analysisvulnerability-analysis+5
6 months ago
CVE-2024-9290 preview

CVE-2024-9290

GitHubrandomrobbiebf/cve-2024-9290

Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2024-5452 preview

CVE-2024-5452

GitHubskrkcb2/cve-2024-5452

Detailed technical analysis of CVE-2024-5452, a remote code execution vulnerability in PyTorch Lightning via DeepDiff delta property pollution, with…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
Previous1…969798…100Next