
awesome-pentest
A collection of awesome penetration testing resources and tools

A collection of awesome penetration testing resources and tools

Curated collection of proof-of-concept exploits for 16 CVEs targeting web applications (ASUS, D-Link, Netgear, TP-Link, Xiaomi) and Wi-Fi WPA3-SAE,…

Exploit scripts for CVE-2024-28397, a js2py sandbox escape that executes arbitrary Python code to spawn a reverse shell on a target endpoint.

A collection of useful resources for hacking WordPress and it's plugins and themes


Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

Curated collection of proof-of-concept exploits for web vulnerabilities including cross-site scripting and SQL injection, with detailed technical…

Awesome information for WebSockets security research

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.

Curated vulnerability research repository with in-depth writeups, PoC scripts, and IOC detection tools for real-world security incidents like…

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Collection of Proof of Concepts and Potential Targets for #ShellShocker

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…