#1Static and dynamic code analysis, SAST, DAST, and code review tools.
Kitploit recommended

CVE-2022-22947 exploit script

Dolibarr 17.0.0 PHP Code Injection Exploit

PoC and analysis for Kibana Prototype Pollution RCE (CVE-2019-7609).

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.


Technical Details and Exploit for CVE-2024-11392

redos

Repository dedicated to CVE-2022-25313, a vulnerability in Expat 2.1.0, providing analysis and potential exploitation code.

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

Proof-of-concept exploit for CVE-2010-2387, a privilege escalation vulnerability in GNOME Display Manager (GDM). Includes C source code targeting the…

CVE-2018-7600.

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

Exploit for Jenkins CVE-2016-9299, a remote code execution vulnerability in the Jenkins CLI. Provides proof-of-concept code for security testing and…

Proof of Concept for CVE-2020-14295.

CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS

Spring Framework RCE exploit (CVE-2022-22965) with analysis code and educational walkthrough for understanding the vulnerability and exploitation…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) targeting Java applications via JNDI injection for remote code execution.