Cheatsheets
Ready-to-copy payloads, bypasses and commands. A quick reference for every vulnerability type.
XSS Cheatsheet
Cross-Site Scripting
SSRF Cheatsheet
Server-Side Request Forgery
SQLi Cheatsheet
SQL Injection
IDOR Cheatsheet
Insecure Direct Object Reference
CSRF Cheatsheet
Cross-Site Request Forgery
Open Redirect Cheatsheet
Open Redirect
XXE Cheatsheet
XML External Entity
Path Traversal Cheatsheet
Directory Traversal / LFI
CORS Cheatsheet
Cross-Origin Resource Sharing
OAuth Cheatsheet
OAuth / OpenID Connect
Race Condition Cheatsheet
Race Conditions
File Upload Cheatsheet
File Upload Vulnerabilities
GraphQL Cheatsheet
GraphQL API Security
WebSockets Cheatsheet
WebSocket Attacks
SSTI Cheatsheet
Server-Side Template Injection
Command Injection Cheatsheet
OS Command Injection
NoSQL Injection Cheatsheet
NoSQL Injection (MongoDB)
JWT Cheatsheet
JSON Web Token Attacks
Want more complete guides with methodology and real cases?
View full guideshunters training
labs from real hacks
completions
paid out for these bugs
The checklist I run on every new target
47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.
Unsubscribe in one click, from any email.
Stop reading about bugs and start hunting them
Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime