Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k19h 6m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k5h 45m ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k16 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k1 day ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
778 results
CVE-2024-3094_xz_check preview

CVE-2024-3094_xz_check

GitHubhackerhermanos/cve-2024-3094_xz_check

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…

vulnerability-scannersvulnerability-analysisscripting-automation+2
92 years ago
CVE-2023-51385_test preview

CVE-2023-51385_test

GitHubltmthink/cve-2023-51385_test

一个验证对CVE-2023-51385

vulnerability-analysisexploitationweb-application-exploitation+2
72 years ago
log4j-recognizer preview

log4j-recognizer

GitHubscitotec/log4j-recognizer

A Java helper to identify log4j in the current classpath

defensive-toolsvulnerability-analysissupply-chain-security
24 years ago
CVE-2021-30005-POC preview

CVE-2021-30005-POC

GitHubatorralba/cve-2021-30005-poc

Proof-of-concept demonstrating arbitrary command execution via malicious virtual environment activation scripts in PyCharm before 2020.3.4,…

vulnerability-analysiscode-analysisexploitation+2
25 years ago
xz-backdoor-CVE-2024-3094-Check preview

xz-backdoor-CVE-2024-3094-Check

GitHubbella-bc/xz-backdoor-cve-2024-3094-check

Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor

vulnerability-scannersvulnerability-analysissupply-chain-security+2
22 years ago
CVE-2024-32002-EXP preview

CVE-2024-32002-EXP

GitHub10cks/cve-2024-32002-exp

Bash PoC for CVE-2024-32002 that exploits Git clone with malicious submodules and symlinks to execute arbitrary commands on Windows and macOS.

vulnerability-analysisexploitationweb-security+3
22 years ago
CVE-2021-32804 preview

CVE-2021-32804

GitHubyamory/cve-2021-32804

Docker-based reproduction environment for CVE-2021-32804, a path traversal vulnerability in node-tar affecting npm, with step-by-step exploitation…

container-securityvulnerability-analysisexploitation+2
15 years ago
CVE-2022-21668-Pipenv-RCE-vulnerability preview

CVE-2022-21668-Pipenv-RCE-vulnerability

GitHubsreeram281997/cve-2022-21668-pipenv-rce-vulnerability

Detailed analysis of CVE-2022-21668, a critical RCE vulnerability in Pipenv's requirements.txt parsing, including bug code, exploit mechanics, and…

vulnerability-analysisexploitationweb-security+3
14 years ago
CVE-2024-24590 preview

CVE-2024-24590

GitHubjunnythemarksman/cve-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously…

payload-generationvulnerability-analysisexploitation+3
12 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubhelsecert/cve-2021-44228

Norwegian-language guide to Log4j vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, CVE-2019-17571) with detection…

vulnerability-analysissupply-chain-securityeducation+3
14 years ago
chk_log4j preview

chk_log4j

GitHubgcmurphy/chk_log4j

Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228

static-analysisvulnerability-scannersvulnerability-analysis+2
14 years ago
CVE-2007-4559 preview

CVE-2007-4559

GitHubdepers-rus/cve-2007-4559

Proof-of-concept demonstrating CVE-2007-4559 path traversal in Python's tarfile module, allowing arbitrary file overwrite via malicious TAR archives.

vulnerability-analysiscode-analysisexploitation+2
11 year ago
CVE-2025-48384-test preview

CVE-2025-48384-test

GitHubbeishanxueyuan/cve-2025-48384-test

Reproduction of CVE-2025-48384 demonstrating a Git submodule path traversal vulnerability, with step-by-step commands to recreate the exploit.

vulnerability-analysiscode-analysisexploitation+1
11 year ago
cve-2020-27955 preview

cve-2020-27955

GitHubtheth1nk3r/cve-2020-27955

cve-2020-27955

payload-generationvulnerability-analysisexploitation+2
15 years ago
pac4j-check preview

pac4j-check

GitHubxiaoqimikko/pac4j-check

Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot.…

static-analysisvulnerability-scannersdevsecops+1
15 days ago
poc-rebar3 preview

poc-rebar3

GitHubvulnbe/poc-rebar3

Shell injection in Rebar3

vulnerability-analysisexploitationpenetration-testing+1
6 years ago
CVE-2026-26830 preview

CVE-2026-26830

GitHubzebberncve/cve-2026-26830

Advisory for pdf-image ⌯⌲ 10 000 weekly downloads

vulnerability-analysiscode-analysisexploitation+3
6 months ago
CVE-2026-0848 preview

CVE-2026-0848

GitHubhyperps/cve-2026-0848

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

vulnerability-analysiscode-analysisexploitation+3
5 months ago
Previous1…404142…44Next