#bugbounty (30 Repositories)
Ranked open-source repositories tagged with #bugbounty, scored by pull request acceptance likelihood and maintainer engagement velocity.
23.9%
17.8h
30 repositories tagged #bugbounty
hahwul/jwt-hack
JSON Web Token Hack Toolkit
hahwul/dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
elementalsouls/Claude-BugHunter
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
edoardottt/csprecon
Discover new target domains using Content Security Policy
j3ssie/osmedeus
A Modern Orchestration Engine for Security
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
caido/caido
🚀 Caido releases, wiki and roadmap
projectdiscovery/subfinder
Fast passive subdomain enumeration tool.
reddelexc/hackerone-reports
Top disclosed reports from HackerOne
halilkirazkaya/arsenal-ng
The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.
0xPugal/fuzz4bounty
1337 Wordlists for Bug Bounty Hunting
Autumn-27/ScopeSentry
ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes
edoardottt/secfiles
My useful files for penetration tests, security assessments, bug bounty and other security related stuff
rix4uni/medium-writeups
This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL
rix4uni/cvemapping
This repo Gathers all available cve exploits from github.⚠️ Be careful Malware.
topscoder/nuclei-wordfence-cve
80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
eslam3kl/SQLiDetector
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
projectdiscovery/awesome-search-queries
Community curated list of search queries for various products across multiple search engines.
jaeles-project/gospider
Gospider - Fast web spider written in Go
infobyte/emploleaks
An OSINT tool that helps detect members of a company with leaked credentials
InfoSecWarrior/Offensive-Payloads
List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.
003random/getJS
A tool to fastly get all javascript sources/files
matty69v/Bug-Bounty-Agents
AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes
1N3/PrivEsc
A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.
teknogeek/ssrf-sheriff
A simple SSRF-testing sheriff written in Go
commixproject/commix
Automated All-in-One OS Command Injection Exploitation Tool
MindPatch/lorsrf
Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:
Brum3ns/firefly
Black box fuzzer for web applications
ethicalhackingplayground/bxss
Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.