
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Tool designed to scan a list of websites for a known vulnerability in the PHPUnit framework, specifically the CVE-2017-9841 vulnerability.

Exploit for CVE-2025-34085

Security advisories published by Enable Security


This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Simple File List – Unauthenticated RCE Exploit (CVE-2025-34085)


A go-exploit for Apache ActiveMQ CVE-2023-46604

PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing…

This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list…

This repository contains all the payloads

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)

An All-In-One Pure Python PoC for CVE-2021-44228