This is the data that powers the PortSwigger URL validation bypass cheat sheet.
☆59Feb 5, 2026Updated 2 months ago
Alternatives and similar repositories for url-cheatsheet-data
Users that are interested in url-cheatsheet-data are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Quick overview of the domain.☆60Apr 3, 2026Updated 2 weeks ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆16Jul 17, 2024Updated last year
- Proof of Concepts for unsafe deserialization in Ruby☆17Oct 17, 2024Updated last year
- ☆31Jan 31, 2026Updated 2 months ago
- I created this to dump challenge for CTF that I participated☆12May 26, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Exploit POC for CVE-2024-22026 affecting Ivanti EPMM "MobileIron Core"☆14May 15, 2024Updated last year
- Blind XSS SVG☆10Mar 27, 2023Updated 3 years ago
- Execute codes From XSLT☆16Dec 28, 2016Updated 9 years ago
- Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security☆178Mar 25, 2026Updated 3 weeks ago
- source code of XCTF 2019 Final web task "tfboys"☆30Nov 21, 2022Updated 3 years ago
- CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection☆17Sep 16, 2024Updated last year
- Slim dockerized Android ndk☆12Mar 3, 2023Updated 3 years ago
- A tool for adding new lines to files, skipping duplicates and written in Rust!☆21May 8, 2025Updated 11 months ago
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆227Jul 24, 2025Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Burp extension to fuzz/brute force GenAI/LLM prompts using a list of various payloads.☆32Sep 4, 2025Updated 7 months ago
- Differential testing framework for HTTP implementations☆928Jan 21, 2026Updated 2 months ago
- ☆13Sep 15, 2024Updated last year
- Content-Type Research☆661Jun 29, 2025Updated 9 months ago
- Extract GraphQL operations from javascript☆23Mar 18, 2026Updated last month
- ☆38Dec 14, 2024Updated last year
- CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scr…☆643Apr 12, 2026Updated last week
- Testnet exchange - near identical mirror to the prod exchange | Rest API + WS + Matching Engine☆13Sep 1, 2024Updated last year
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆19Jun 9, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A lightweight Python 3 Nmap wrapper that doesn't try too hard. Gracefully handles any Nmap command, providing access to all output types …☆17Apr 1, 2026Updated 2 weeks ago
- Scrape domain names from SSL certificates of arbitrary hosts☆690Mar 31, 2024Updated 2 years ago
- Challenges I created for CTFs☆25Dec 21, 2025Updated 3 months ago
- Custom Trickest Workflows☆12Oct 26, 2023Updated 2 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆965Dec 31, 2021Updated 4 years ago
- Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)☆89Jul 5, 2022Updated 3 years ago
- ☆22Jun 16, 2019Updated 6 years ago
- Adobe Experience Manager (AEM) hacking toolkit☆111Sep 26, 2025Updated 6 months ago
- A collection of pyjails!☆28Dec 15, 2025Updated 4 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Query various sources for CVE proof-of-concepts☆53Jun 1, 2023Updated 2 years ago
- A shortlist of core ServiceNow tables.☆15Oct 16, 2023Updated 2 years ago
- ☆18Feb 14, 2019Updated 7 years ago
- Python Agent is a Python application probe of DongTai IAST, which collects method invocation data during runtime of Python application by…☆22Jun 6, 2022Updated 3 years ago
- Extensor is a command-line tool designed to help users quickly gather URLs containing specific file extensions from a given source (e.g.,…☆10Mar 13, 2024Updated 2 years ago
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆30Nov 30, 2025Updated 4 months ago
- A tool to parse, deduplicate, and query multiple port scans.☆57Aug 11, 2023Updated 2 years ago