payloadbox / xss-payload-list
π― Cross Site Scripting ( XSS ) Vulnerability Payload List
β6,592Updated 6 months ago
Alternatives and similar repositories for xss-payload-list:
Users that are interested in xss-payload-list are comparing it to the libraries listed below
- π― Command Injection Payload Listβ3,081Updated 6 months ago
- π― SQL Injection Payload Listβ5,136Updated 6 months ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies andβ¦β3,711Updated 3 years ago
- HTTP parameter discovery suite.β5,376Updated last month
- A list of interesting payloads, tips and tricks for bug bounty hunters.β6,013Updated last year
- ππ¦ Dalfox is a powerful open-source XSS scanner and utility focused on automation.β3,880Updated last week
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.β8,337Updated last year
- A Tool for Domain Flyoversβ5,694Updated 2 years ago
- A toolkit for testing, tweaking and cracking JSON Web Tokensβ5,546Updated 5 months ago
- A python script that finds endpoints in JavaScript filesβ3,789Updated 9 months ago
- Awesome XSS stuffβ4,832Updated 2 months ago
- Web application fuzzerβ6,019Updated 5 months ago
- Scripted Local Linux Enumeration & Privilege Escalation Checksβ7,140Updated last year
- A curated list of amazingly awesome Burp Extensionsβ3,040Updated 2 months ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.β5,232Updated 5 months ago
- Top disclosed reports from HackerOneβ4,098Updated 3 weeks ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Toolβ3,850Updated 8 months ago
- "Can I take over XYZ?" β a list of services and how to claim (sub)domains with dangling DNS records.β4,964Updated last week
- Linux privilege escalation auditing toolβ5,739Updated 11 months ago
- A collection of custom security tools for quick needs.β3,164Updated last year
- Automatic SSRF fuzzer and exploitation toolβ3,051Updated 7 months ago
- Automated All-in-One OS Command Injection Exploitation Tool.β4,682Updated this week
- An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!β1,685Updated 10 months ago
- AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.β5,260Updated 7 months ago
- A repository with 3 tools for pwn'ing websites with .git repositories availableβ3,902Updated last year
- Monitor linux processes without root permissionsβ5,059Updated 2 years ago
- Fast web fuzzer written in Goβ13,030Updated 6 months ago
- Fast subdomains enumeration tool for penetration testersβ10,029Updated 5 months ago
- Git All the Payloads! A collection of web attack payloads.β3,657Updated last year
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.β5,106Updated 2 months ago