Welcome to the Bug Hunter's Wordlists repository! ππ This repository serves as a comprehensive collection of essential wordlists utilized by bug hunters, penetration testers, and security enthusiasts during their reconnaissance and vulnerability assessment processes.
β155May 17, 2024Updated 2 years ago
Alternatives and similar repositories for Wordlist-Hub
Users that are interested in Wordlist-Hub are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BUG HUNTING/WEB APPLICATION PENTESTING CHECKLISTβ15May 30, 2023Updated 3 years ago
- β25Nov 18, 2023Updated 2 years ago
- BugSquasher Bug Bounty Tools Listβ22Feb 2, 2023Updated 3 years ago
- Template Nuclei SSTIβ34Nov 18, 2025Updated 8 months ago
- Passively check for XSS character encodingsβ20Mar 9, 2026Updated 4 months ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- This Repositories contains list of One Liners with Descriptions and Installation requirementsβ511Jun 28, 2025Updated last year
- All-in Fuzzer. Burp suite extension for auto fuzzing params, headers, bodyβ36Apr 9, 2026Updated 3 months ago
- Bcheck scripts for Burpβ31Aug 7, 2024Updated last year
- Contains nuclei templates for security testing and POCs.β17Oct 19, 2024Updated last year
- an exploit of Server-side request forgery (SSRF)β55Aug 2, 2024Updated last year
- Shodan Dorks 2023β245Jan 13, 2025Updated last year
- ScanExp automates the scanning of any machine's open ports via the ip address and performs a brute force attack on ports 20, 21 for the Fβ¦β27Oct 14, 2023Updated 2 years ago
- DomainTrail is a fast subdomain enumeration tool that uses effective passive and active techniques.β41Apr 18, 2024Updated 2 years ago
- Simple-XSS is a multiplatform cross-site scripting (XSS) vulnerability exploitation tool.β49Jul 2, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headersβ314Mar 31, 2024Updated 2 years ago
- A simple utility to quickly gather historic Port and CVE exposures from an IP range.β41Nov 12, 2023Updated 2 years ago
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzingβ142Jun 27, 2023Updated 3 years ago
- Burp extension used to snip any header from all the requests.β25Nov 12, 2023Updated 2 years ago
- i will upload more templates here to share with the comunity.β572Apr 17, 2024Updated 2 years ago
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflowsβ308Sep 8, 2023Updated 2 years ago
- G3nius Tools Sploit is a penetration testing tool with a lot of plugins for advanced cybersecurity attacks. User-friendly, Easy and modulβ¦β63Apr 13, 2024Updated 2 years ago
- Subprober is a powerful and efficient subdomain scanning tool written in Python. With the ability to handle large lists of subdomains. Thβ¦β267May 17, 2026Updated 2 months ago
- LFI-FINDER is an open-source tool available on GitHub that focuses on detecting Local File Inclusion (LFI) vulnerabilitiesβ302Jan 7, 2024Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean β’ AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- This repository contains random Nuclei templates I've created. Most of them based on recent security issues and exploits.β18May 21, 2024Updated 2 years ago
- Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.β800Jun 11, 2026Updated last month
- Python/Bash automation customization script designed to automate the reconnaissance processβ21Jan 28, 2024Updated 2 years ago
- My Priv8 Nuclei Templatesβ346May 12, 2024Updated 2 years ago
- β254May 25, 2021Updated 5 years ago
- An automated script to extract hidden images from Tecno Camon Xβ12Sep 23, 2023Updated 2 years ago
- β432Jun 29, 2026Updated last month
- Generate password spraying lists based on the pwdLastSet-attribute of users.β56Dec 6, 2023Updated 2 years ago
- Self-hosted passive subdomain continous monitoring tool.β172Jan 30, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Mine URLs from Browser's Heap Snapshot for fun and profitβ66Aug 9, 2023Updated 2 years ago
- A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hiddeβ¦β450Apr 24, 2026Updated 3 months ago
- Nodesub is a command-line tool for finding subdomains in bug bounty programsβ149Aug 1, 2024Updated last year
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.β107May 2, 2024Updated 2 years ago
- Burp Suite extension that makes your life easier by tucking the headers out of the way, so you can see the body content right away withouβ¦β40Oct 23, 2023Updated 2 years ago
- Encoder PHP webshell to bypass WAF using XOR operations.β56Aug 2, 2023Updated 2 years ago
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzerβ387May 19, 2023Updated 3 years ago