
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

This is a webshell open source project

Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…


This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

An All-In-One Pure Python PoC for CVE-2021-44228

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

WebLogic Exploit

Here Are Some Bug Bounty Resource From Twitter

Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)

Security advisories published by Enable Security

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

SecRep Is a Repository That Contain Useful Intrusion, Penetration and Hacking Archive Including Tools List, Cheetsheet and Payloads

[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization

PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing…

Python script that sends CVE-2021-44228 log4j payload requests to url list

A go-exploit for Apache ActiveMQ CVE-2023-46604