
AwesomeXSS
Curated collection of XSS payloads, polyglots, bypass techniques, and educational resources for web security testing and learning.

Curated collection of XSS payloads, polyglots, bypass techniques, and educational resources for web security testing and learning.

Collection of Bambda scripts for Burp Suite enabling custom table filters, columns, Repeater actions, match-and-replace rules, and scan checks to…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Collects webshell payloads in ASP, ASPX, PHP, JSP, JSPX, Python, and Perl for web application security testing, red-team operations, and payload…

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.

Curated directory of hacking tutorials, tools, and resources covering penetration testing, reverse engineering, web security, network analysis,…

Curated collection of XML External Entity (XXE) payloads for security testing and exploitation of XXE vulnerabilities in web applications during…

Curated collection of web application payloads for penetration testing, vulnerability exploitation, and security assessments, covering XSS, SQLi,…

Index of 8,000+ public GitHub proof-of-concept repositories mapped to CVE identifiers, with a searchable web interface and REST API for security…

Structured study notes covering web hacking fundamentals, common vulnerabilities, penetration testing techniques, and defensive security, with…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

One-liner bug bounty workflows for recon, subdomain enumeration, endpoint extraction, and web vulnerability scanning using Nuclei, sqlmap, and CVE…

Automated detection and tracking of fake engagement on GitHub — daily CI, zero infrastructure

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Curated collection of web attack payloads for XSS, SQLi, command injection, and more. Includes fuzzing lists, password wordlists, and CTF-sourced…

Curated collection of image-based payloads for authorized red-team testing and security education, with HTML examples for generating or embedding web…

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…