
Bug_Bounty_writeups
Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

🐶 A curated list of Web Security materials and resources.

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

CVE disclosure for stored cross-site scripting (XSS) in SWISH Prolog up to v2.2.0, enabling arbitrary code execution and account takeover via crafted…

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

Tips and Tutorials for Bug Bounty and also Penetration Tests.

Technical Reference to multiple relay techniques

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…