Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k9h 54m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k5 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k18h 22m ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k15 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k0 days ago
NewestRelevanceMost popularRecently updated
778 results
opencode-secure preview

opencode-secure

GitHubbarrersoftware/opencode-secure

Security-hardened fork of OpenCode - Fixes CVE-2026-22812 (CVSS 8.8 RCE) that upstream refuses to patch

vulnerability-analysiscode-analysisdevsecops+1
68 months ago
CVE-2026-21852-PoC preview

CVE-2026-21852-PoC

GitHubatiilla/cve-2026-21852-poc

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

static-analysisvulnerability-analysisexploitation+5
246 months ago
Sovereign-Echo-33017 preview

Sovereign-Echo-33017

GitHubsimoesctt/sovereign-echo-33017

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

vulnerability-analysisexploitationweb-application-exploitation+4
6 months ago
NodeJS-Tar-Symlink-Exploit-CVE-2026-29786 preview

NodeJS-Tar-Symlink-Exploit-CVE-2026-29786

GitHubrohitberiwala/nodejs-tar-symlink-exploit-cve-2026-29786

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

vulnerability-analysisexploitationweb-security+1
16 months ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubjvr2022/cve-2026-31802

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

vulnerability-analysisexploitationweb-security+1
16 months ago
CVE-2026-29786 preview

CVE-2026-29786

GitHubjvr2022/cve-2026-29786

Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

vulnerability-analysiscode-analysisexploitation+2
16 months ago
CVE-2026-22807_Range preview

CVE-2026-22807_Range

GitHubotakuliu/cve-2026-22807_range

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

payload-generationvulnerability-analysisexploitation+3
7 months ago
CVE-2026-21436 preview

CVE-2026-21436

GitHubosmancanvural/cve-2026-21436

Proof-of-concept exploit for CVE-2026-21436, demonstrating path traversal in Solus OS eopkg package manager allowing arbitrary file write during…

vulnerability-analysisexploitationmalware-analysis+2
8 months ago
demo-cve-2026-4821 preview

demo-cve-2026-4821

GitHubopenexecution-coder/demo-cve-2026-4821

Demonstrates AI agent-driven CVE remediation with cryptographic provenance tracking, showcasing detection, analysis, human approval, and verification…

vulnerability-analysissupply-chain-securityeducation+2
7 months ago
CVE-2026-33634-Scanner preview

CVE-2026-33634-Scanner

GitHubfevar54/cve-2026-33634-scanner

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

ioc-managementvulnerability-scannersnetwork-security+4
5 months ago
next-picomatch-cve-repro preview

next-picomatch-cve-repro

GitHubbelazy167/next-picomatch-cve-repro

Minimal repro for Next.js 16.2.4 bundling picomatch 4.0.3 (CVE-2026-33671)

vulnerability-analysissupply-chain-securityeducation+1
5 months ago
cve-2026-31900-lab preview

cve-2026-31900-lab

GitHubbatosay1337lab/cve-2026-31900-lab

CVE-2026-31900 Vulnerable Lab - psf/black GitHub Action RCE

vulnerability-analysisexploitationweb-security+3
15 months ago
docker-socket-risk-demos preview

docker-socket-risk-demos

GitHubashleyt3/docker-socket-risk-demos

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

cloud-infrastructure-securityvulnerability-scannerscontainer-security+3
5 months ago
loguccino preview

loguccino

GitHub3pplus/loguccino

Scan and patch tool for CVE-2021-44228 and related log4j concerns.

vulnerability-scannersvulnerability-analysisdevsecops+1
4 years ago
fickling preview

fickling

GitHubtrailofbits/fickling

A Python pickling decompiler and static analyzer

static-analysisvulnerability-analysiscode-analysis+5
6705 days ago
hardware-compliance-handbook preview

hardware-compliance-handbook

GitHubplatanor/hardware-compliance-handbook

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

iot-securitycloud-securityhardware-security+3
286 days ago
CVE-2026-52617 preview

CVE-2026-52617

GitHubs1ko/cve-2026-52617

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

vulnerability-analysiscode-analysisexploitation+1
28 days ago
modelscan preview

modelscan

GitHubprotectai/modelscan

Protection against Model Serialization Attacks

defensive-toolsstatic-analysisvulnerability-scanners+5
7747 months ago
Previous1…456…44Next