
payloads
Git All the Payloads! A collection of web attack payloads.

Git All the Payloads! A collection of web attack payloads.

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

ZIP File Raider - Burp Extension for ZIP File Payload Testing

Proof-of-concept for CVE-2025-9951 demonstrating controlled callback execution in FFmpeg via JPEG 2000 component-mapping mismatch. Includes write-up,…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

High-performance black-box fuzzer for web applications with built-in payload engine, request verification, tampering, encoding, and advanced…

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

Proof-of-concept and lab harness for CVE-2026-8461, an out-of-bounds write in FFmpeg's MagicYUV decoder, with payload generator and Qt demo player.

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

C-based exploit for CVE-2025-46817, a Redis integer overflow vulnerability, enabling crash detection and potential RCE via Lua unpack() payload.

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…


eeroOS Ethernet Interface Denial of Service Vulnerability (CVE-2023-5324)

Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db