awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to xsuperbug/payloads

Open-source alternatives to Payloads

26 open-source projects similar to xsuperbug/payloads, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Payloads alternative.

  • 0xsobky/hackvault0xsobky avatar

    0xsobky/HackVault

    2,025View on GitHub↗

    A container repository for my public web hacks!

    JavaScript
    View on GitHub↗2,025
  • 7iosecurity/xss-payloads7ioSecurity avatar

    7ioSecurity/XSS-Payloads

    49View on GitHub↗

    XSS Payloads

    View on GitHub↗49
  • camoufl4g3/sqli-payload-fuzz3rC

    camoufl4g3/SQLi-payload-Fuzz3R

    0View on GitHub↗
    View on GitHub↗0
  • contactleft/sqlifuzzerC

    ContactLeft/sqlifuzzer

    0View on GitHub↗
    View on GitHub↗0
  • cujanovic/content-bruteforcing-wordlistcujanovic avatar

    cujanovic/content-bruteforcing-wordlist

    219View on GitHub↗

    Wordlist for content(directory) bruteforce discovering with Burp or dirsearch

    Python
    View on GitHub↗219
  • cujanovic/crlf-injection-payloadsC

    cujanovic/CRLF-Injection-Payloads

    0View on GitHub↗
    View on GitHub↗0
  • cujanovic/dirsearch-wordlistC

    cujanovic/dirsearch-wordlist

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • cujanovic/open-redirect-payloadscujanovic avatar

    cujanovic/Open-Redirect-Payloads

    661View on GitHub↗

    Open Redirect Payloads

    Shell
    View on GitHub↗661
  • cujanovic/subdomain-bruteforce-listC

    cujanovic/subdomain-bruteforce-list

    0View on GitHub↗
    View on GitHub↗0
  • cujanovic/virtual-host-wordlistC

    cujanovic/Virtual-host-wordlist

    0View on GitHub↗
    View on GitHub↗0
  • danielmiessler/robotsdisalloweddanielmiessler avatar

    danielmiessler/RobotsDisallowed

    1,485View on GitHub↗
    Shell
    View on GitHub↗1,485
  • danielmiessler/seclistsdanielmiessler avatar

    danielmiessler/SecLists

    71,596View on GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHP
    View on GitHub↗71,596
  • firefart/hashcollision-dos-pocF

    FireFart/HashCollision-DOS-POC

    0View on GitHub↗
    View on GitHub↗0
  • foospidy/web-cve-testsF

    foospidy/web-cve-tests

    0View on GitHub↗
    View on GitHub↗0
  • fuzzdb-project/fuzzdbfuzzdb-project avatar

    fuzzdb-project/fuzzdb

    8,819View on GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    View on GitHub↗8,819
  • hybrisdisaster/asphashdosH

    HybrisDisaster/aspHashDoS

    0View on GitHub↗
    View on GitHub↗0
  • ismailtasdelen/command-injection-payload-listI

    ismailtasdelen/command-injection-payload-list

    0View on GitHub↗
    View on GitHub↗0
  • ismailtasdelen/xss-payload-listI

    ismailtasdelen/xss-payload-list

    0View on GitHub↗
    View on GitHub↗0
  • minimaxir/big-list-of-naughty-stringsminimaxir avatar

    minimaxir/big-list-of-naughty-strings

    47,686View on GitHub↗

    This project is a standardized repository of malicious and malformed character sequences designed to stress-test data parsing and sanitization routines. It serves as a security testing corpus and a language-neutral reference for auditing software robustness against injection flaws and unexpected data handling errors across diverse platforms. The dataset functions as a benchmark for input validation, providing a curated collection of edge-case strings that allow developers to identify potential crashes and security vulnerabilities. By decoupling these test vectors from application logic, the r

    Python
    View on GitHub↗47,686
  • nicksanzotta/burpintruderN

    NickSanzotta/BurpIntruder

    0View on GitHub↗
    View on GitHub↗0
  • swisskyrepo/payloadsallthethingsswisskyrepo avatar

    swisskyrepo/PayloadsAllTheThings

    78,434View on GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Pythonbountybugbountybypass
    View on GitHub↗78,434
  • terjanq/tiny-xss-payloadsterjanq avatar

    terjanq/Tiny-XSS-Payloads

    2,370View on GitHub↗

    A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

    JavaScriptbugbountyctfhtml
    View on GitHub↗2,370
  • therook/subbruteTheRook avatar

    TheRook/subbrute

    3,515View on GitHub↗

    A DNS meta-query spider that enumerates DNS records, and subdomains.

    Python
    View on GitHub↗3,515
  • wireghoul/dotdotpwnwireghoul avatar

    wireghoul/dotdotpwn

    1,109View on GitHub↗

    DotDotPwn - The Directory Traversal Fuzzer

    Perl
    View on GitHub↗1,109
  • xmendez/wfuzzxmendez avatar

    xmendez/wfuzz

    6,519View on GitHub↗

    Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism

    Python
    View on GitHub↗6,519
  • xsscx/commodity-injection-signaturesX

    xsscx/Commodity-Injection-Signatures

    0View on GitHub↗
    View on GitHub↗0