Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k12h 52m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k10h 8m ago
grype preview#3

grype

GitHubanchore/grype
12.7k5 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k5 days ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k14 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k4 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k26 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k1 day ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
541 day ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
777 results
NPMAnalysis preview

NPMAnalysis

GitHubal1ex/npmanalysis

NPM Sec Analysis

malware-analysisthreat-intelligencesupply-chain-security+2
9 months ago
Report-XZ-Utils-CVE-2024-3094 preview

Report-XZ-Utils-CVE-2024-3094

GitHubpreacher98/report-xz-utils-cve-2024-3094

Hello,

vulnerability-analysissupply-chain-securitypapers-research+2
2 months ago
cve-2018-6574-exploit preview

cve-2018-6574-exploit

GitHubzerbaliy3v/cve-2018-6574-exploit

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

payload-generationvulnerability-analysisexploitation+2
2 years ago
CVE-2026-45321-Tanstack preview

CVE-2026-45321-Tanstack

GitHubrenewablehacking/cve-2026-45321-tanstack

Educational lab simulating npm supply chain attacks, CI/CD abuse, and install-time code execution via CVE-2026-45321. Hands-on defensive security…

vulnerability-analysismalware-analysissupply-chain-security+2
4 months ago
parquet-avro-rce preview

parquet-avro-rce

GitHubmicrictor/parquet-avro-rce

PoC: CVE-2025-30065 incomplete fix bypass in Apache Parquet Java 1.15.1

vulnerability-analysiscode-analysisexploitation+2
5 months ago
vuln_test_repo_public_ruby_gemfile_cve-2016-6317 preview

vuln_test_repo_public_ruby_gemfile_cve-2016-6317

GitHubkavgan/vuln_test_repo_public_ruby_gemfile_cve-2016-6317

Detects known vulnerabilities in Ruby Gemfile dependencies by scanning for specific CVEs, enabling automated security checks in development pipelines.

static-analysisvulnerability-analysiscode-analysis+2
9 years ago
http-server-node preview

http-server-node

GitHubdannyendortest/http-server-node

Synthetic vulnerable Node.js HTTP server used as a demo target for the EXPOSURE vulnerability scanner, tracking CVE-2021-23797 with a one-click…

vulnerability-scannersvulnerability-analysissupply-chain-security+2
4 months ago
xzutils_backdoor_obfuscation preview

xzutils_backdoor_obfuscation

GitHubthomrgn/xzutils_backdoor_obfuscation

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)

exploitationreverse-engineeringmalware-analysis+4
11 months ago
CVE-2026-0596-Reproduction preview

CVE-2026-0596-Reproduction

GitHubsparshbiswas-ai/cve-2026-0596-reproduction

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

vulnerability-analysisexploitationweb-security+7
4 months ago
cve-tarmageddon preview

cve-tarmageddon

GitHubedera-dev/cve-tarmageddon

Demonstration of CVE-2025-62518: a critical PAX extended header size override bug in tokio-tar and async Rust tar libraries, with reproduction tools…

vulnerability-analysisexploitationfuzzing+3
1911 months ago
hook preview

hook

GitHubamalmurali47/hook

Hook for the PoC for exploiting CVE-2024-32002

vulnerability-analysisexploitationsupply-chain-security+2
182 years ago
trivy-repo preview

trivy-repo

GitHubaquasecurity/trivy-repo

deb/rpm repository for Trivy

vulnerability-scannerscontainer-securitycloud-security+4
121 month ago
xz-backdoor-github preview

xz-backdoor-github

GitHubemirkmo/xz-backdoor-github

History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.

malware-analysisdigital-forensicsthreat-intelligence+3
112 years ago
check-react-rce-cve-2025-55182 preview

check-react-rce-cve-2025-55182

GitHubzihxs/check-react-rce-cve-2025-55182

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

static-analysisvulnerability-scannerscode-analysis+3
69 months ago
CVE-2024-32002-Exploit preview

CVE-2024-32002-Exploit

GitHubbfengj/cve-2024-32002-exploit

Proof-of-concept exploit for CVE-2024-32002, a Git submodule vulnerability enabling arbitrary code execution via crafted repositories and symlinks.

payload-generationexploitationweb-application-exploitation+3
22 years ago
CVE-2017-1000117_wasawasa preview

CVE-2017-1000117_wasawasa

GitHubsasairc/cve-2017-1000117_wasawasa

Minimal test repository demonstrating Git's CVE-2017-1000117 recursive clone vulnerability for educational exploitation verification.

vulnerability-analysisexploitationsupply-chain-security+1
19 years ago
CVE-2026-35204 preview

CVE-2026-35204

GitHubh3ck13r/cve-2026-35204

Proof-of-concept demonstrating a path traversal vulnerability (CVE-2026-35204) in Helm plugin installation, allowing arbitrary file write via crafted…

container-securityvulnerability-analysisexploitation+3
12 months ago
pac4j-check preview

pac4j-check

GitHubxiaoqimikko/pac4j-check

Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot.…

static-analysisvulnerability-scannersdevsecops+1
14 days ago
Previous1…424344Next