
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF


Exploit for CVE-2025-34085


This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Simple File List – Unauthenticated RCE Exploit (CVE-2025-34085)

PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing…

This repository contains all the payloads

Quick access to XXE Payloads

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

An All-In-One Pure Python PoC for CVE-2021-44228

Python script that sends CVE-2021-44228 log4j payload requests to url list

CVE-2004-1769 cPanel Resetpass Remote Command Execution

SecRep Is a Repository That Contain Useful Intrusion, Penetration and Hacking Archive Including Tools List, Cheetsheet and Payloads

WebLogic Exploit