#1Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.
Kitploit recommended

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Network asset discovery and scanning client that integrates nmap and masscan for large-scale asset identification, port scanning, and vulnerability…

UPnP Pentest Toolkit for Windows

Proof of Concept Exploit for vCenter CVE-2021-21972

SMB vulnerability scanner that detects CVE-2019-1040 by sending invalid NTLM authentication packets, enabling MIC Remove relay attacks for domain…

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard

CVE-2021-22205& GitLab CE/EE RCE

WPHunter A Wordpress Vulnerability Scanner

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities.

Vthunting is a tiny script used to generate report about Virus Total hunting and send it by email, slack or telegram.

Use IDA PRO HexRays decompiler with OpenAI(ChatGPT) to find possible vulnerabilities in binaries

CVE-2025-30208-EXP

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

A free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan.

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…