#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Detects and fixes CVE-2025-55182 (React2Shell) in React Server Components and Next.js apps. Scans package versions, suggests safe upgrades, and…
Proof-of-concept exploit for CVE-2025-69599, demonstrating uncontrolled search path element in RayVentory Scan Engine's rvia and ndtrack binaries,…

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

C library for parsing XML, patched for CVE-2022-23852, providing stream-oriented XML parsing with handlers for efficient document processing.

This is the exploit of CVE-2018-6574: go get RCE

Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS

PoC for CVE-2025-62518 demonstrating tar archive smuggling via tokio-tar PAX header parsing, creating malicious payloads and a vulnerable extractor…

A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed…

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

retire.js has a new home

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

deb/rpm repository for Trivy

CVE-2021-44228 server-side fix for minecraft servers.

一个验证对CVE-2023-51385

Proof of concept of CVE-2017-1000117

Curated resource hub for Log4j CVE-2021-44228, covering detection, mitigation, exploitation, and dependency management strategies for the critical…