Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k19h 5m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k5h 44m ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k16 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k1 day ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
778 results
pyscan preview

pyscan

GitHubohaswin/pyscan

python dependency vulnerability scanner, written in Rust.

static-analysisvulnerability-scannerscode-analysis+2
2493 months ago
Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832 preview

Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832

GitHubthedevappsecguy/log4j-mitigation-cve-2021-44228--cve-2021-45046--cve-2021-45105--cve-2021-44832

Log4J CVE-2021-44228 : Mitigation Cheat Sheet

vulnerability-analysiscloud-securitydevsecops+3
24 years ago
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

defensive-toolsstatic-analysisvulnerability-scanners+4
91 year ago
vexhub preview

vexhub

GitHubaquasecurity/vexhub

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

vulnerability-analysisinformation-gatheringdevsecops+2
396 months ago
DonkAI preview

DonkAI

GitHubowasp/donkai

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

vulnerability-analysisweb-securityctf+6
123 months ago
rauc-1.5-integration preview
Archived

rauc-1.5-integration

GitHubrauc/rauc-1.5-integration

integration examples for the CVE-2020-25860 fix

embedded-systems-securityiot-securityvulnerability-analysis+3
15 years ago
cryptoptic preview

cryptoptic

GitHubnationwide-group-oss/cryptoptic

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

defensive-toolsstatic-code-analysisvulnerability-analysis+6
2 days ago
capslock preview

capslock

GitHubgoogle/capslock

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

static-analysisvulnerability-analysiscode-analysis+2
1.2k2 days ago
XZ-Utils_CVE-2024-3094 preview

XZ-Utils_CVE-2024-3094

GitHubmrbuglf/xz-utils_cve-2024-3094

XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)

vulnerability-analysisexploitationmalware-analysis+3
2 years ago
LR-WebPKI preview

LR-WebPKI

GitHubnserser/lr-webpki

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

cloud-infrastructure-securitycryptographysupply-chain-security+2
25 days ago
syft preview

syft

GitHubanchore/syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

static-analysiscontainer-securityvulnerability-analysis+3
9.6k1 day ago
criticality_score preview

criticality_score

GitHubossf/criticality_score

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

information-gatheringutilities-frameworkssupply-chain-security+1
1.5k28 days ago
vulns-2026-fatfs-chance preview

vulns-2026-fatfs-chance

GitHubrunzeroinc/vulns-2026-fatfs-chance

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and…

embedded-systems-securityiot-securityvulnerability-analysis+8
412 months ago
react2shell preview

react2shell

GitHubcahyod/react2shell

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

static-analysisvulnerability-scannerscode-analysis+2
19 months ago
remic preview

remic

GitHubknqyf263/remic

Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependencies

vulnerability-scannerssupply-chain-security
237 years ago
modelscan preview

modelscan

GitHubprotectai/modelscan

Protection against Model Serialization Attacks

defensive-toolsstatic-analysisvulnerability-scanners+5
7747 months ago
nuguard preview

nuguard

GitHubnuguardai/nuguard

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+8
2117h 14m ago
CVE-2017-8046 preview

CVE-2017-8046

GitHubbkhablenko/cve-2017-8046

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

vulnerability-analysiscode-analysisweb-application-exploitation+3
8 years ago
Previous1…456…44Next