Skip to content

$ cyberwordlists --list

The catalog of security wordlists.

A curated hub of passwords, usernames, fuzzing payloads, and subdomain lists — with inline previews, one-click copy, direct downloads, and an in-browser generator.

Open the generator

367 lists·8 categories·copy or download

Browse the catalog

/wordlists →
Categories
Size
367 of 367 lists
Web Content17 KB
.DS_Store Path Wordlist

Common file and directory names typically extracted from leaked macOS .DS_Store files. Useful as a content-discovery seed list for sites that may have exposed .DS_Store metadata.

ffufgobusterferoxbusterdirsearch
Details
Passwords1,134 lines (9 KB)
1337 Speak Permutations

Leetspeak permutations of common base words (e.g. apple -> app|3). Useful for cracking passwords that substitute letters with symbols/digits.

hashcatjohn
Details
Passwords2 KB
2020 Top 200 Most Used Passwords

The 200 most used passwords of 2020 as published in annual breach analyses. A tiny, high-yield list for fast credential spraying.

hashcatjohnhydramedusa
Details
Passwords499 lines (3 KB)
500 Worst Passwords

The classic 500 worst passwords list. Tiny and ideal for fast online brute-force checks against login services.

hydramedusancrack
Details
Web Content35.4 KB
Adobe AEM Paths 2021 (SecLists)

Adobe Experience Manager (AEM) / CQ paths and dispatcher bypass URLs for enumerating AEM instances and content nodes.

ffufgobusterferoxbuster
Details
Web Content6.6 KB
Adobe ColdFusion Paths (SecLists)

Adobe ColdFusion administrative and component paths (CFIDE, cfdocs, administrator, BlazeDS) for fingerprinting and probing ColdFusion installs.

ffufgobusterferoxbusterwfuzz
Details
Web Content3.5 KB
Apache Tomcat Paths (SecLists)

Apache Tomcat manager, host-manager, and internal paths (META-INF, WEB-INF, manager/html) for enumerating Tomcat servers.

ffufgobusterferoxbusterdirb
Details
Web Content8,533 lines (67 KB)
Apache Web Server Content

Apache-specific paths and files including .htaccess, log locations, cgi directories, and server-status endpoints. Use when fingerprinting or targeting Apache servers.

ffufgobusterferoxbusterdirsearch
Details
API & Endpoints1.6 KB
API Actions (SecLists)

Common API action/verb names (add, delete, activate, login) used to construct and fuzz API operation paths.

ffufferoxbusterkiterunner
Details
API & Endpoints4.3 KB
API Endpoints (SecLists)

Curated list of common REST API endpoint paths (api/auth, api/users, etc.) for content discovery against API roots.

ffufgobusterferoxbusterkiterunner
Details
API & Endpoints177.1 KB
API Endpoints Resources (SecLists)

Large list of API resource/method tokens and identifiers harvested from real APIs, useful for deep API endpoint fuzzing.

ffufferoxbusterkiterunnerwfuzz
Details
API & Endpoints20.4 KB
API Objects (SecLists)

Common API object/noun names (users, orders, products, ids) for building or fuzzing RESTful resource paths.

ffufferoxbusterkiterunner
Details
Passwords5 KB
Arabic Common Passwords (Top 487)

The top 487 most common passwords used by Arabic-speaking users, including Arabic transliterated names appended with digits. A compact list for Middle East and North Africa targets.

hashcatjohnhydramedusa
Details
API & Endpoints149.6 KB
Arjun Parameters Large

Arjun's large HTTP parameter-name wordlist (~26k) for discovering hidden request parameters.

arjunffufwfuzz
Details
API & Endpoints94.3 KB
Arjun Parameters Medium

Arjun's medium HTTP parameter-name wordlist for balanced hidden-parameter discovery.

arjunffufwfuzz
Details
Fuzzing608 KB
ASP.NET Default MachineKeys

Known/leaked ASP.NET validationKey,decryptionKey pairs (machineKey secrets) for testing ViewState deserialization and forged-token attacks.

burpnuclei
Details
Subdomains28.0 MB
Assetnote 2m-subdomains

Assetnote's curated ~2-million-entry subdomain wordlist derived from CommonSpeak2 and scan data, a popular mid-size list for DNS brute-forcing.

purednsdnsxamass
Subdomains134.3 MB
Assetnote best-dns-wordlist (9.5M)

Assetnote's flagship 9.5-million-entry DNS/subdomain brute-force wordlist, frequency-ordered from large-scale internet scans. One of the most effective mass subdomain bruteforce lists available.

purednsdnsxamass
Fuzzing28 KB
Big List of Naughty Strings

The well-known Big List of Naughty Strings: reserved words, special characters, Unicode edge cases, script/SQL snippets and other inputs that often break naive software. A general-purpose input-validation fuzzing list.

wfuzzburpffuf
Details
Subdomains1.4 MB
Bitquark Subdomains Top 100000

Bitquark's top 100,000 subdomain labels mined from DNS datasets and public data. A widely-used, high-quality list ordered by real-world frequency.

ffufgobusteramasspuredns
Details
Fuzzing462 B
Bo0oM File Extension Fuzz List

Bo0oM's curated file-extension fuzzing list (backup, config, source, archive suffixes) for discovering sensitive files via extension brute-forcing.

ffufferoxbusterwfuzz
Details
Usernames789.6 KB
Brazil Top 100000 Names

The 100,000 most common Brazilian given names, lowercased one per line. Useful for username enumeration and name-based password guessing against Brazilian/Portuguese-speaking targets.

hydramedusakerbrutencrack
Details
API & Endpoints52.9 KB
Burp Parameter Names (SecLists)

Wordlist of HTTP parameter names compiled from Burp Suite, used for fuzzing hidden GET/POST parameters.

ffufarjunwfuzzferoxbuster
Details
Passwords3.1 MB
Cain and Abel Default Wordlist

The default password dictionary bundled with the Cain & Abel Windows recovery tool, containing roughly 306,000 entries. A well-rounded general-purpose cracking list.

hashcatjohnhydramedusa
Details
Passwords16 KB
Carders.cc Leaked Passwords

Passwords recovered from the breach of the carders.cc carding forum, skewed heavily toward German-language passwords. Useful for profiling underground-forum and German-user credentials.

hashcatjohnhydramedusa
Details
Web Content118 KB
CGI-bin Scripts

Large list of classic cgi-bin scripts and legacy CGI endpoints (.cgi, .exe, .pl, .cfm). Useful for discovering vulnerable legacy CGI handlers on older web servers.

ffufgobusterdirbwfuzz
Details
Passwords81 KB
Chinese Common Passwords (Top 10000)

The 10,000 most common Chinese-user passwords ordered by frequency, including patterns like 5201314 and 7758521. Useful for targeting Chinese-speaking accounts.

hashcatjohnhydramedusa
Details
Usernames6.2 KB
CIRT Default Usernames

Default and built-in account usernames collected from the cirt.net default password database. Useful for spraying common vendor/admin accounts across many devices and services.

hydramedusancrackkerbrute
Details
Passwords1,041 lines (8 KB)
CIRT.net Default Password Collection

Default passwords aggregated from the CIRT.net default-password database. Ideal for default-credential checks across many devices.

hydramedusancrack
Details
Web Content360 B
CMS Configuration File Paths (SecLists)

Paths to configuration files of common CMSes (wp-config.php, configuration.php, settings.php, app/etc/env.php) for hunting credential-bearing config disclosure.

ffufgobusterferoxbusterdirsearch
Details
Subdomains7.9 MB
Combined Subdomains

A large 653,920-entry list merging multiple subdomain sources for maximum coverage. Best run with a fast resolver such as puredns for thorough enumeration.

ffufpurednsamassdnsx
Details
Fuzzing20 KB
Command Execution (PayloadsAllTheThings)

Command injection payloads combining shell separators, quoting and encoded newlines with commands like id and cat /etc/passwd. For detecting OS command execution in web parameters.

wfuzzburpffuf
Details
Fuzzing918 KB
Command Injection (Commix)

Large OS command-injection payload set generated in the style of the Commix tool, using echo-marker probes and many separator/encoding combinations. For detecting shell command injection sinks.

wfuzzburpffuf
Details
Credentials2.2 KB
Common Admin Usernames (plaintext:base64 pairs)

Common privileged account names (root, administrator, superuser, etc.) each paired with its Base64 encoding, useful for HTTP Basic-Auth and other base64-encoded credential fields. Format is plaintextname:base64name per line.

hydrawfuzzffufpatator
Details
API & Endpoints1.1 KB
Common API Endpoints (mazen160)

Mazen Gamal's compact list of common API endpoint and version paths for quick API surface enumeration.

ffufgobusterferoxbuster
Details
Web Content336 lines (4.5 KB)
Common DB Backups

Targeted list of common database backup filenames and archive extensions (sql, tar.gz, zip, 7z, etc.). Useful for hunting exposed database dumps left on web servers.

ffufgobusterferoxbusterdirsearch
Details
Web Content172 B
Common HTTP Ports (SecLists)

List of common HTTP/HTTPS service ports for web service discovery and port-based fuzzing across non-standard web ports.

ffufwfuzz
Details
Web Content5,163 lines (74 KB)
Common PHP Filenames

Large collection of common .php filenames seen across PHP applications and frameworks. Tailored for enumerating PHP-based sites.

ffufgobusterferoxbusterdirsearch
Details
Credentials826 B
Common SNMP Community Strings

A short, high-value list of the most common default SNMP community strings (public, private, vendor defaults) for quick SNMP credential checks.

onesixtyonesnmpwalk
Details
Web Content4,750 lines (38 KB)
Common Web Content (common.txt)

The classic SecLists common.txt of frequently encountered web paths, including dotfiles, VCS folders, and admin endpoints. A reliable default wordlist for everyday discovery.

ffufgobusterferoxbusterdirb
Details
Fuzzing588 B
CRLF Injection (PayloadsAllTheThings)

CRLF injection payloads using various encodings of carriage-return/line-feed to inject a Set-Cookie header. For testing HTTP response splitting and header injection.

wfuzzburpffuf
Details
Fuzzing173 B
curl-supported URL protocols

URL scheme/protocol prefixes supported by curl (file, gopher, dict, ftp, etc.) for probing SSRF and URL-parsing bugs.

ffufburpsuitewfuzz
Details
Passwords9,999 lines (81 KB)
Dark Web 2017 Top 10000

Top 10,000 passwords aggregated from dark web breach dumps in 2017. Good modern complement to older common-password lists.

hashcatjohnhydra
Details
Passwords14.4 MB
darkc0de wordlist

The classic darkc0de wordlist, a large mixed dictionary of passwords, dictionary words and symbol sequences long bundled with pentest distros.

hashcatjohnhydramedusa
Fuzzing2.1 KB
Database & Application Error Strings

Pattern-matching strings for detecting database, ASP.NET and server error messages in HTTP responses, useful for SQLi/error-leak detection grep lists.

nucleiburpwfuzz
Details
Passwords45,012 lines (396 KB)
Dates 1900-2020 (DDMMYYYY)

Every date from 1900 to 2020 in DDMMYYYY form. Effective against date-of-birth style passwords and numeric PIN-pattern guesses.

hashcatjohn
Details
Subdomains3.3 KB
Deepmagic Prefixes Top 500

The top 500 DNS prefixes compiled by deepmagic.com from large-scale reverse-DNS data. A tiny, quick-pass list useful for ISP and infrastructure naming patterns.

ffufgobusterdnsx
Details
Subdomains591.2 KB
Deepmagic Prefixes Top 50000

The top 50,000 DNS prefixes compiled by deepmagic.com from large-scale reverse-DNS data. A broad list strong on ISP, hosting and infrastructure naming conventions.

ffufgobusterpurednsdnsx
Details
Passwords1,335 lines (10 KB)
Default Passwords (SecLists)

Curated list of vendor/device default passwords. Use against routers, IoT, and appliances that ship with factory credentials.

hydramedusancrack
Details
Web Content87,664 lines (708 KB)
DirBuster directory-list 2.3 Small

The smallest DirBuster 2.3 directory list, a priority-ordered case-sensitive set of paths found on at least 3 different hosts. A fast, low-noise starting point for directory brute-forcing.

ffufgobusterferoxbusterdirb
Details
Web Content207,643 lines (1.8 MB)
DirBuster directory-list lowercase 2.3 Medium

The all-lowercase variant of the DirBuster 2.3 medium directory list, useful against case-insensitive web servers. Priority-ordered by entries found on at least 2 different hosts.

ffufgobusterferoxbusterdirsearch
Details
Web Content81,643 lines (661 KB)
DirBuster directory-list lowercase 2.3 Small

The all-lowercase small DirBuster 2.3 directory list for case-insensitive targets. Entries are priority-ordered and were found on at least 3 different hosts.

ffufgobusterferoxbusterdirb
Details
Web Content1.7 MB
DirBuster directory-list-1.0

The original first-draft DirBuster 1.0 unordered case-sensitive list, containing entries found on at least two hosts. A broad legacy directory/file discovery wordlist.

ffufgobusterferoxbuster
Web Content15.3 MB
DirBuster directory-list-2.3-big

The full case-sensitive DirBuster 2.3 directory/file brute-force list, priority-ordered with entries found on at least one host. The canonical large web-content discovery wordlist.

ffufgobusterferoxbusterwfuzz
Web Content220,559 lines (1.9 MB)
DirBuster directory-list-2.3-medium

The legendary DirBuster medium list of directory and file names ordered by real-world hit frequency. The default deep-dive wordlist for thorough web directory brute-forcing.

ffufgobusterferoxbusterdirb
Details
Fuzzing8.6 KB
Directory Traversal (PayloadsAllTheThings)

Path/directory traversal payloads targeting Windows win.ini with many encoding and double-encoding variations of ../ and backslash sequences. For testing path-traversal filters and WAF bypass.

ffufwfuzzburp
Details
Web Content450 KB
Django CMS Content

File and directory paths derived from the Django CMS / Django framework source tree, including admin, templates and Python module paths. Useful for content discovery against Django-based sites.

ffufgobusterferoxbusterdirsearch
Details
Subdomains5.7 KB
dnscan Subdomains Top 1000

The 1,000 most frequently observed subdomain labels curated by the dnscan project, ideal for fast, high-hit-rate subdomain brute-forcing.

ffufgobusteramassdnsx
Details
Subdomains61.4 KB
dnscan Subdomains Top 10000

The top 10,000 subdomain labels from the dnscan project, a broader frequency-ranked list for deeper DNS subdomain discovery.

ffufgobusteramassdnsx
Details
Subdomains11.7 KB
DNSRecon Namelist

The default subdomain brute-force namelist bundled with the dnsrecon enumeration tool, blending numeric prefixes with common service hostnames.

ffufgobusteramassdnsx
Details
Subdomains33.0 KB
DNSRecon Subdomains Top 5000

dnsrecon's top 5,000 most common subdomain labels derived from the top-1-million dataset, a balanced mid-size list for subdomain brute-forcing.

ffufgobusteramassdnsx
Details
API & Endpoints678 B
Docker Engine API Paths (SecLists)

Docker Engine remote API endpoints (containers/json, images, build, exec, debug/pprof) for probing exposed Docker daemons.

ffufgobusterferoxbuster
Details
Web Content113.9 KB
DotNetNuke (DNN) Paths (SecLists)

DotNetNuke (DNN) CMS file and directory paths (admin containers, skins, modules, install) for enumerating DNN installations.

ffufgobusterferoxbuster
Details
Fuzzing1.5 KB
Double URL-Encoded Hex Bytes

All 256 byte values double-URL-encoded (%25xx) for testing double-decoding bugs, WAF bypass and filter evasion.

ffufwfuzzburp
Details
Web Content36.4 KB
Drupal 7.20 URL List (SecLists)

Differential URL list of files shipped with Drupal 7.20 (includes, modules, themes) for fingerprinting Drupal core paths.

ffufgobusterferoxbuster
Details
Web Content14 KB
Drupal Themes Fuzz

List of Drupal theme directory paths under themes/. Useful for enumerating installed Drupal themes during CMS assessments and version fingerprinting.

ffufgobusterferoxbusterdirsearch
Details
Web Content58,242 lines (3.5 MB)
Drupal Web Content

Comprehensive list of Drupal core files, modules, themes, and translation files. Built for deep enumeration of Drupal-powered sites.

ffufgobusterferoxbusterdirsearch
Details
Passwords6.4 KB
EliteHacker Leaked Passwords

Passwords leaked from the EliteHacker forum breach. A compact, security-community-flavored list useful for cracking and credential guessing.

hashcatjohnhydra
Details
Fuzzing1.1 KB
Email Top 100 Domains (SecLists)

Top 100 email provider domains, useful for generating email/IDN payloads, account-enumeration tests, and email-parser fuzzing.

wfuzzffufburp
Details
Passwords71 KB
FaithWriters Leaked Passwords

Passwords from the breach of the FaithWriters Christian writing community, rich in religious and faith-themed terms. Useful for targeting religiously-themed password patterns.

hashcatjohnhydramedusa
Details
Usernames7.0 KB
Family Names - USA Top 1000

Top 1000 most common US family (last) names. Useful for generating username candidates and for password-spray / AD account enumeration in surname-based naming conventions.

hydramedusakerbrute
Details
Usernames6.8 KB
Female Names - USA Top 1000

Top 1000 most common US female first names. Useful for building username permutations and for Active Directory user enumeration in first-name-based schemes.

hydramedusakerbrute
Details
Subdomains9.7 KB
Fierce Default Hostlist

The built-in subdomain brute-force list shipped with the modern Python fierce DNS reconnaissance tool, covering common hostnames and numeric prefixes.

ffufgobusteramassdnsx
Details
Subdomains14.3 KB
Fierce Hostlist

The classic 2,280-entry hostname list shipped with the Fierce DNS reconnaissance tool. A compact starter list of common host prefixes.

ffufgobusteramassdnsx
Details
Passwords1.2 KB
Finnish Common Passwords (Top 150)

Top 150 most common Finnish-language passwords from the Pwdb dataset, including local profanity and keyboard patterns. Useful for Finnish-locale credential guessing.

hashcatjohnhydramedusa
Details
Usernames27.5 KB
Forenames - India Top 1000

Top 1000 most common Indian first names. Useful for region-specific username generation and account enumeration against India-based organizations.

hydramedusakerbrute
Details
Fuzzing899 B
Format String Payloads (Jhaddix)

Format-string attack payloads (%p, %x, %n and repeated/long variants) for probing C-style printf vulnerabilities. For testing native back ends and logging sinks.

wfuzzburp
Details
Passwords78,977 lines (850 KB)
Fortinet 2021 Leaked Passwords

VPN passwords leaked in the 2021 Fortinet SSL-VPN dump. Highly relevant for testing enterprise/VPN credential reuse.

hashcatjohnhydra
Details
Passwords10,000 lines (82 KB)
Four-Digit PIN Codes by Frequency

All 10,000 four-digit PINs sorted by real-world frequency with occurrence counts. Use for PIN brute-forcing or masks where 4-digit PINs apply.

hashcatjohn
Details
Passwords151 KB
French Common Passwords (Top 20000)

The 20,000 most common French-language passwords ordered by frequency, including French keyboard patterns like azerty. Ideal for French-speaking targets.

hashcatjohnhydramedusa
Details
Credentials955 B
FTP Better Default Passlist

Curated user:password combos for FTP services covering common vendor and appliance defaults. Drop-in for FTP brute-force tooling that accepts colon-separated credential pairs.

hydramedusancrackpatator
Details
Fuzzing126 KB
Fully Qualified Java Classes (SecLists)

Comprehensive list of fully-qualified Java class names, useful for Java deserialization, JNDI/Log4j gadget discovery, and class-name parameter fuzzing.

burpffufwfuzz
Details
Web Content3 KB
FuzzDB ADFS Predictable Paths

Predictable paths for Microsoft Active Directory Federation Services (ADFS), including App_Code, resource files and localized resx assets. Helps fingerprint and discover content on ADFS portals.

ffufgobusterferoxbusterdirb
Details
Fuzzing1.2 KB
FuzzDB Blind SQLi MSSQL WHERE Clause

Time-based blind SQL injection payloads for MSSQL WHERE clauses using WAITFOR DELAY across escalating quote and parenthesis breakout contexts.

sqlmapffufburp
Details
Fuzzing1.8 KB
FuzzDB Blind SQLi MySQL WHERE Clause

Time-based blind SQL injection payloads for MySQL WHERE clauses using BENCHMARK() delays across varied quote/parenthesis breakout contexts.

sqlmapffufburp
Details
Web Content30 KB
FuzzDB Bot Control Panel Filenames

Filenames associated with malware/botnet command-and-control panels and dropped PHP files. Helps locate C2 panels and backdoor artifacts on compromised servers.

ffufgobusterferoxbusterdirb
Details
Fuzzing443 B
FuzzDB Business Logic Common Method Names

Common application method/action names (add, admin, auth, change, delete, etc.) for fuzzing hidden business-logic endpoints, RPC methods, and undocumented actions.

ffufwfuzzburp
Details
Web Content137 KB
FuzzDB CGI Cross-Platform Paths

Large cross-platform list of CGI scripts and known-vulnerable CGI request paths for fuzzing inside cgi-bin and script directories. Includes legacy CGI exploits and traversal probes.

ffufgobusterferoxbusterwfuzz
Details
Web Content2 KB
FuzzDB CGI Microsoft/Windows Paths

Windows-specific CGI executables and known-vulnerable script paths (cart32.exe, cmd.exe probes, fpsrvadm.exe) for fuzzing IIS-style cgi/scripts directories.

ffufgobusterferoxbusterwfuzz
Details
API & Endpoints1 KB
FuzzDB Common HTTP/REST Methods

Common REST/API resource names and action verbs (account, balance, block, change, check) for fuzzing API endpoints and method names. Useful for discovering undocumented API routes.

ffufwfuzzgobuster
Details
Fuzzing1.2 KB
FuzzDB CRLF Injection

CRLF injection payloads for HTTP response splitting and header injection using encoded carriage-return/line-feed sequences, UTF-7 XSS, and Content-Type smuggling.

ffufwfuzzburpnuclei
Details
Fuzzing2.4 KB
FuzzDB Format String Attacks

Format-string attack payloads combining printf-style conversion specifiers (%s, %p, %x, %n) in long repeating sequences to probe for format-string vulnerabilities and memory disclosure.

ffufwfuzzburp
Details
Web Content1 KB
FuzzDB FrontPage Server Extensions Paths

Predictable paths exposed by Microsoft FrontPage Server Extensions, including author/admin DLLs, .pwd credential files and _fpclass artifacts. Useful for legacy IIS/FrontPage fingerprinting.

ffufgobusterferoxbusterdirb
Details
Fuzzing374 B
FuzzDB HTTP Protocol Methods

HTTP request methods including standard verbs and WebDAV/extension methods for testing method-based access control bypasses and verb tampering.

ffufwfuzzburp
Details
Fuzzing101 B
FuzzDB Integer Overflows

Boundary integer values (signed/unsigned 32-bit limits in decimal and hex) for testing integer-overflow and off-by-one conditions in numeric parameters.

ffufwfuzzburp
Details
Fuzzing49 KB
FuzzDB JSON Fuzzing

Malformed and edge-case JSON documents (null bytes, nested arrays, prototype/class pollution keys, oversized structures) for stress-testing JSON parsers and API endpoints.

ffufwfuzzburp
Details
Web Content21 KB
FuzzDB Kitchensink Directories

Broad general-purpose list of common web directory names for brute-force content discovery across any web server. A catch-all directory wordlist covering numbers, admin areas and typical app folders.

ffufgobusterferoxbusterdirb
Details
Fuzzing310 B
FuzzDB LDAP Injection

LDAP injection metacharacters and filter-breakout payloads in both raw and URL-encoded forms, including wildcard and objectClass enumeration filters.

ffufwfuzzburp
Details
Web Content1 KB
FuzzDB Login Page Locations

Common login and administration page filenames across multiple languages and extensions (asp, aspx, cfm, jsp, php, pl, py, rb). Ideal for quickly locating authentication endpoints.

ffufgobusterferoxbusterdirb
Details
Web Content3 KB
FuzzDB Lotus Notes/Domino NSF Paths

Predictable .nsf databases and adm-bin executables exposed by IBM Lotus Notes/Domino servers. Targets sensitive databases and admin interfaces during discovery.

ffufgobusterferoxbusterdirb
Details
Fuzzing494 B
FuzzDB MongoDB NoSQL Injection

MongoDB NoSQL injection payloads using $where JavaScript evaluation, $ne/$or operators, and regex match tricks to bypass auth and extract data.

ffufwfuzzburp
Details
Fuzzing448 B
FuzzDB MSSQL SQL Injection Detection

Microsoft SQL Server injection detection payloads including comment terminators, xp_cmdshell probes, and UNION-based @@version disclosure tests.

sqlmapffufburp
Details
Fuzzing1.9 KB
FuzzDB Null Byte Representations

Many encodings of the null byte (%00, \0, \x00, \u0000, etc.) for testing null-byte injection, string truncation, and filter-bypass conditions.

ffufwfuzzburp
Details
Fuzzing606 B
FuzzDB Open Redirect URL Template

Templated open-redirect query strings and path variants (url=, next=, schemeless //, encoded slashes) with a {target} placeholder for the attacker-controlled destination host.

ffufwfuzzburpnuclei
Details
Fuzzing7.8 KB
FuzzDB Oracle SQL Injection Detection

Oracle-specific SQL injection detection and out-of-band payloads leveraging utl_http, utl_inaddr.get_host_address, and SYS catalog queries for error-based and exfiltration testing.

sqlmapffufburp
Details
Fuzzing805 B
FuzzDB OS Command Injection Template

Templated OS command injection prefixes/separators using a {cmd} placeholder, covering shell delimiters, redirects, and CRLF-encoded breakouts. Substitute your command into the template before fuzzing.

ffufwfuzzburp
Details
Web Content1 KB
FuzzDB Password File Locations

Predictable locations of password and credential files such as htpasswd, passwd, secring and config.php. Targets exposed secrets during web content discovery.

ffufgobusterferoxbusterdirb
Details
Fuzzing52 KB
FuzzDB Path Traversal 8-Deep Exotic Encoding

Directory-traversal payloads up to 8 levels deep using exotic and mixed encodings (hex, URL, double-encoded, slash/backslash variants) with a {FILE} placeholder for the target file.

ffufwfuzzburp
Details
Fuzzing744 B
FuzzDB PHP Magic Hashes

PHP magic-hash strings that hash to 0e... patterns, exploiting loose (==) type-juggling comparisons to bypass authentication and hash checks.

burpffufwfuzz
Details
Web Content99 KB
FuzzDB PHP-Nuke Predictable Paths

Exhaustive list of predictable file and directory paths for the PHP-Nuke CMS, including admin scripts, modules, blocks and language files. Useful for fingerprinting and content discovery on PHP-Nuke installs.

ffufgobusterferoxbusterdirb
Details
Fuzzing2.7 KB
FuzzDB Server-Side Includes Generic

Server-Side Includes (SSI) injection directives (#config, #echo, #exec, #include) for testing SSI processing and information disclosure on web servers.

ffufwfuzzburp
Details
Web Content1 KB
FuzzDB Sun App Server / GlassFish Paths

Predictable servlets, JSP sample apps and admin endpoints for Sun Application Server and GlassFish. Helps fingerprint and discover content on these Java app servers.

ffufgobusterferoxbusterdirb
Details
Web Content1 KB
FuzzDB Unix Dotfiles

Unix hidden dotfiles commonly exposed via misconfigured web roots, including .bash_history, .htaccess, .ssh and .DS_Store. Some entries also probe for known dotfile-related vulnerabilities.

ffufgobusterferoxbusterdirb
Details
Web Content9 KB
FuzzDB Web Shell Filenames

Filenames commonly used by uploaded web shells and backdoors, plus sensitive config files attackers target. Useful for detecting compromised hosts or discovering planted backdoors.

ffufgobusterferoxbusterdirb
Details
Fuzzing1.1 KB
FuzzDB Windows Commands

List of Windows shell command names useful for testing command-injection sinks and validating remote code execution on Windows targets.

ffufwfuzzburp
Details
Fuzzing2.9 KB
FuzzDB XML Attacks (XXE)

XML attack payloads including XXE external-entity file reads (/etc/passwd, boot.ini, /dev/random DoS), CDATA-wrapped SQLi/XSS, and MS data-island injections.

burpffufwfuzz
Details
Fuzzing209 B
FuzzDB XPath Injection

XPath injection payloads using boolean tautologies, node-count expressions, and name() probes to bypass authentication and enumerate XML document structure.

ffufwfuzzburp
Details
Fuzzing3.7 KB
FuzzDB XSS Polyglot

Ashar Javed's XSS polyglot and its component fragments wrapped in many HTML contexts (input, img, a, math, iframe, style, textarea) to fire across multiple injection points at once.

burpffufwfuzz
Details
Fuzzing1.8 KB
FuzzDB XSS URI Handler Payloads

Cross-browser XSS payloads abusing custom URI scheme handlers (aim:, firefoxurl:, navigatorurl:, res:) to achieve script execution or local command launch.

burpffufwfuzz
Details
Fuzzing1.2 KB
Generic Blind SQL Injection

Time-based blind SQL injection payloads using sleep() and WAITFOR DELAY across multiple quoting and parenthesis contexts. Designed for inference attacks where no error output is returned.

sqlmapwfuzzburp
Details
Fuzzing5.3 KB
Generic SQL Injection

Database-agnostic SQL injection probes mixing error-based, boolean, time-based and stacked-query payloads. A solid general-purpose detection list for unknown back ends.

sqlmapwfuzzburp
Details
Passwords89 KB
German Common Passwords (Top 10000)

The 10,000 most common German-language passwords ordered by frequency. Useful for targeting German-speaking users and DACH-region accounts.

hashcatjohnhydramedusa
Details
Fuzzing29.0 KB
GitHub dorks for secret hunting

GitHub search dorks targeting leaked API keys, credentials, and config files in public source-code repositories.

github-searchtrufflehogcustom-scripts
Details
Web Content1.8 KB
GitLab Paths (SecLists)

GitLab admin and instance endpoints (admin/application_settings, audit_events, deploy_keys) for enumerating self-hosted GitLab servers.

ffufgobusterferoxbuster
Details
Web Content1.6 KB
Grafana Paths (SecLists)

Grafana admin and API endpoints (admin/users, api/datasources, api/dashboards) for enumerating Grafana dashboards and settings.

ffufgobusterferoxbuster
Details
API & Endpoints1.6 KB
GraphQL Endpoints (SecLists)

Common GraphQL endpoint and IDE paths (graphql, graphiql, altair, playground) for locating GraphQL interfaces.

ffufgobusterferoxbuster
Details
Passwords1.2 KB
Greek Common Passwords (Top 150)

Top 150 most common Greek-language passwords from the Pwdb dataset. Useful for locale-specific attacks against Greek targets.

hashcatjohnhydramedusa
Details
Passwords2,351 lines (24 KB)
Hak5 Leaked Passwords

Passwords leaked from a Hak5 forum breach. A compact real-world leak list useful for testing and supplementing larger lists.

hashcatjohnhydra
Details
API & Endpoints1.8 KB
HashiCorp Consul API paths

HashiCorp Consul HTTP API endpoints for discovering exposed service-mesh, KV-store, and agent management interfaces.

ffufgobusterferoxbuster
Details
Passwords1.1 KB
Hebrew Common Passwords (Top 150)

Top 150 most common Hebrew-locale passwords from the Pwdb dataset. Useful for credential guessing against Israeli/Hebrew-speaking users.

hashcatjohnhydramedusa
Details
Passwords51,286 lines (705 KB)
Heralding Honeypot Passwords 2019

Username,password pairs captured by the Heralding honeypot in 2019. Represents what automated attackers actually try in the wild.

hydramedusancrack
Details
Passwords1.2 KB
Hindi Common Passwords (Top 150)

Top 150 most common Hindi/India-region passwords from the Pwdb dataset. Useful for locale-aware attacks against Indian targets.

hashcatjohnhydramedusa
Details
Passwords226,081 lines (1.9 MB)
Honeynet Captured Passwords

Passwords captured by honeypot/honeynet sensors observing real attacker login attempts. Great for default and bot-targeted credentials.

hashcatjohnhydra
Details
Passwords914.8 KB
Honeypot Multi-Source Captured Passwords

Passwords captured across multiple honeypot sensors (fabian-fingerle.de), reflecting what real automated attackers try. Strong for bot/default-credential and SSH brute-force simulation.

hashcatjohnhydramedusa
Details
Passwords85.3 KB
Hotmail Leaked Passwords

Passwords from the 2009 Hotmail phishing leak, skewed toward Spanish-speaking users. Useful for real-world email-account password cracking.

hashcatjohnhydra
Details
Fuzzing688 B
HTTP Request Methods / Verbs (SecLists)

List of HTTP request methods/verbs including WebDAV and uncommon verbs, useful for HTTP verb tampering, method-based access-control bypass, and 403/405 testing.

ffufwfuzzburpnuclei
Details
Credentials241 B
Huawei Router Default Passwords

Default passwords shipped on Huawei routers and ONT/HGW gateways. Vendor-specific list for Huawei device login testing.

hydramedusancrackpatator
Details
Passwords1.1 KB
Hungarian Common Passwords (Top 150)

Top 150 most common Hungarian-language passwords from the Pwdb dataset. Useful for locale-specific attacks against Hungarian targets.

hashcatjohnhydramedusa
Details
Credentials135 B
IBM DB2 Better Default Password List

Default user:password pairs for IBM DB2 instances (db2inst1, db2admin, dasusr1, etc.). Targets out-of-the-box DB2 service accounts.

hydramedusapatator
Details
Web Content11 KB
IBM WebSphere Application Server Paths

IBM WebSphere Application Server endpoints, servlet patterns and sample-application paths (.do, .jsp, services/*, WSDL). Useful for enumerating WebSphere admin and sample app surfaces.

ffufgobusterferoxbusterwfuzz
Details
Web Content216 lines (4.9 KB)
IIS Web Server Content

Microsoft IIS-specific paths, sample ASP applications, and classic directory traversal payloads. Targeted for enumerating Windows/IIS web servers.

ffufgobusterferoxbusterdirsearch
Details
Passwords1.2 KB
Indonesian Common Passwords (Top 150)

Top 150 most common Indonesian-language passwords from the Pwdb dataset. Useful for locale-aware attacks against Indonesian targets.

hashcatjohnhydramedusa
Details
Passwords1 KB
Italian Common Passwords (Top 150)

The 150 most common Italian-language passwords derived from the Pwdb dataset, including football clubs and Italian first names. A fast quick-hit list for Italian targets.

hashcatjohnhydramedusa
Details
Subdomains152.3 KB
Italian Subdomains (SecLists)

A region-focused subdomain wordlist of 20,000 hostnames commonly seen on Italian organizations' DNS, useful for localized subdomain brute-forcing.

ffufgobusteramassdnsx
Details
Passwords1.3 KB
Japanese Common Passwords (Top 150)

Top 150 most common Japanese-locale passwords from the Pwdb dataset. Useful for credential guessing against Japanese users.

hashcatjohnhydramedusa
Details
Web Content365 B
JBoss / WildFly Paths (SecLists)

JBoss/WildFly administrative endpoints such as jmx-console, web-console, and the JMXInvokerServlet used to enumerate JBoss application servers.

ffufgobusterferoxbuster
Details
Web Content526 B
Jenkins / Hudson Paths (SecLists)

Jenkins/Hudson CI endpoints (script console, cli, configure, credentials, asynchPeople) for discovering Jenkins management interfaces.

ffufgobusterferoxbuster
Details
Passwords21 KB
John the Ripper Default Wordlist

The classic default wordlist shipped with the John the Ripper password cracker. A small, fast list of common passwords and dictionary words.

johnhashcathydramedusa
Details
Web Content224 lines (5.5 KB)
Joomla Plugins Fuzz

List of Joomla component paths under components/com_*. Useful for enumerating installed Joomla extensions during CMS assessments.

ffufgobusterferoxbusterdirsearch
Details
Fuzzing49 KB
JSON Fuzzing

Malformed and edge-case JSON bodies for fuzzing JSON parsers and API endpoints, including null bytes, type confusion and nested structures. For robustness and injection testing of JSON APIs.

wfuzzburp
Details
Passwords9,608 lines (83 KB)
Keyboard Walk Combinations

Generated keyboard-walk patterns (e.g. zaq1xsw2). Targets passwords built from adjacent-key sequences on the keyboard.

hashcatjohn
Details
API & Endpoints1.1 KB
Keycloak IAM Paths (SecLists)

Keycloak identity and access management admin/realm endpoints for enumerating realms, clients, users, and role mappings.

ffufgobusterferoxbuster
Details
API & Endpoints2.1 KB
Kubernetes API Paths (SecLists)

Kubernetes API server endpoints (api, apis, version, healthz, metrics) for probing exposed kube-apiserver and kubelet interfaces.

ffufgobusterferoxbuster
Details
Web Content1.7 KB
Laravel Paths (All Levels)

Common Laravel framework file and directory paths (bootstrap, routes, config, artisan, .env.example) expanded across path depths. Useful for fingerprinting Laravel applications and spotting exposed config or environment files.

ffufgobusterferoxbusterdirsearch
Details
Fuzzing247 B
LDAP Injection Fuzzing

LDAP injection metacharacters and filter payloads (both raw and URL-encoded) such as wildcard objectclass/mail filters. For testing directory-backed authentication and search.

wfuzzburpffuf
Details
Fuzzing9.6 KB
LFI Files with Null-Byte Terminator

Local file inclusion target paths with a %00 null-byte appended to bypass extension-appending filters in vulnerable include() handlers.

ffufwfuzzburp
Details
Fuzzing22 KB
LFI Linux Files (GracefulSecurity)

A broad catalog of interesting Linux files to target via Local File Inclusion, from config files to credential stores. Ideal for enumerating readable files through an LFI sink.

ffufwfuzzburp
Details
Fuzzing22 KB
LFI Path-To-Test (LFISuite)

Local File Inclusion path-to-test payloads bundled from LFISuite, covering common Unix/Linux files and PHP wrapper/proc tricks. Useful for parameter fuzzing to detect file disclosure.

ffufwfuzzburp
Details
Fuzzing930 lines (32 KB)
LFI Payloads (Jhaddix)

Jhaddix's curated Local File Inclusion and path-traversal payloads (encoded /etc/passwd, boot.ini, and more). Feed into a fuzzer's parameter position to test for LFI and directory traversal.

ffufwfuzzferoxbuster
Details
Web Content426.0 KB
LFI Windows File Paths (SecLists)

Large list of sensitive Windows absolute file paths (logs, config, registry hives) for Local File Inclusion and path traversal testing.

ffufwfuzzferoxbuster
Details
Web Content5.8 KB
Liferay DXP Default Portlets

Liferay DXP control-panel portlet management URLs (group/control_panel/manage?p_p_id=...). Useful for enumerating default portlets reachable on a Liferay DXP portal.

ffufgobusterferoxbusterwfuzz
Details
Fuzzing14.1 KB
Login bypass strings

Authentication-bypass payloads combining SQL injection, default credentials and logic tricks to fuzz login forms.

ffufburpsuitewfuzz
Details
Web Content867.1 KB
Magento Sitemap Paths (SecLists)

Magento e-commerce file and directory map (skin, media, app, includes, downloader) for enumerating Magento store installations.

ffufgobusterferoxbuster
Details
Usernames6.5 KB
Male Names - USA Top 1000

Top 1000 most common US male first names. Useful for generating username candidates and for password-spray / AD account enumeration in first-name-based naming conventions.

hydramedusakerbrute
Details
Fuzzing1.2 KB
Malicious Code / Webshell Grep Strings

Strings for finding backdoor shells, rootkits and dangerous PHP functions (system, eval, base64_decode) in source or responses during detection scans.

nucleiburp
Details
Passwords30.8 MB
md5decryptor-uk wordlist

A large dictionary of plaintext passwords recovered by the md5decrypter.co.uk service, useful for MD5 and general hash cracking.

hashcatjohnhydra
Fuzzing816 B
Metacharacters (FuzzDB)

Special characters and metacharacter sequences (XML entities, format specifiers, null markers, broken markup) for general input-handling and injection fuzzing. A grab-bag for triggering parser errors.

wfuzzburpffuf
Details
Passwords314.5 KB
Most Popular Letter Passes

A large list of the most popular alphabetic/symbol-prefixed password strings. Useful as a broad supplemental dictionary for offline cracking.

hashcatjohnhydra
Details
Credentials1.0 KB
MSSQL Better Default Passlist

Default user:password combinations for Microsoft SQL Server, including many sa-account defaults from shipped applications. Ideal for credential testing against exposed MSSQL instances.

hydramedusapatator
Details
Fuzzing1.0 KB
MSSQL Injection (FuzzDB)

Microsoft SQL Server specific injection payloads including xp_cmdshell execution, login/role creation and version disclosure unions. Targets back ends confirmed to be MSSQL.

sqlmapburp
Details
Usernames51 B
MSSQL Usernames (Nansh0u / Guardicore)

Microsoft SQL Server account names observed in the Nansh0u campaign analyzed by Guardicore. A short, high-signal list of service accounts targeted against exposed MSSQL instances.

hydramedusapatator
Details
Passwords790 KB
muslimMatch Leaked Passwords

Passwords recovered from the breach of the muslimMatch dating site, containing many Islamic and Arabic-themed terms. Useful for community-specific password profiling.

hashcatjohnhydramedusa
Details
Passwords37,126 lines (346 KB)
MySpace Leaked Passwords

Passwords from the MySpace breach, notable for trailing-digit patterns (e.g. name1). Useful for studying complexity-policy workarounds.

hashcatjohnhydra
Details
Credentials343 B
MySQL Better Default Passlist

Default user:password combinations for MySQL/MariaDB, mostly root-account defaults shipped by appliances and applications. Drop-in for credential testing against exposed MySQL services.

hydramedusapatator
Details
Subdomains49.2 MB
n0kovo subdomains huge (3M)

The 3-million-entry 'huge' variant of n0kovo's subdomain wordlist, built from billions of observed DNS names and frequency-ranked. Designed for mass DNS brute-forcing with puredns.

purednsdnsxamass
Passwords99,840 lines (816 KB)
NCSC 100k Most Used Passwords

The UK National Cyber Security Centre's list of the 100,000 most-breached passwords (from Have I Been Pwned). Excellent broad coverage of real-world weak passwords.

hashcatjohnhydra
Details
Passwords1,437 lines (14 KB)
NordVPN Leaked Passwords

Passwords from a NordVPN credential-stuffing leak. Real user passwords useful as a small supplementary list.

hashcatjohnhydra
Details
Passwords1.2 KB
Norwegian Common Passwords (Top 150)

Top 150 most common Norwegian-language passwords from the Pwdb dataset. Good for targeting Norwegian users in regional engagements.

hashcatjohnhydramedusa
Details
Fuzzing605 B
NoSQL Injection

NoSQL (primarily MongoDB) injection payloads using $where, $ne, $or operators and JavaScript match() expressions. For testing document databases and JSON APIs.

wfuzzburpffuf
Details
Fuzzing696 B
NoSQL injection payloads

MongoDB/NoSQL injection payloads using $where, $ne, and $or operators to bypass auth and extract data.

burpsuiteffufnosqlmap
Details
Web Content37.1 MB
OneListForAll Short (six2dez)

The 'short' build of OneListForAll, a de-duplicated mega-merge of many fuzzing/content wordlists (SecLists, assetnote, fuzzdb and more) for one-shot web content discovery.

ffufferoxbustergobuster
Fuzzing2.2 KB
Open Redirect Encoded Payloads

Open-redirect payloads using URL-encoding, backslash and slash-prefix tricks to bypass redirect validation and reach attacker domains.

ffufwfuzzburpnuclei
Details
Fuzzing8.5 KB
Open Redirect Payloads (PayloadsAllTheThings)

Open redirect bypass payloads using whitelist-evasion tricks (@ tricks, encoded slashes, double slashes) against a placeholder whitelisteddomain.tld. Designed for fuzzing redirect/return-url parameters.

ffufwfuzzburp
Details
Web Content3.0 MB
OpenCart Paths (All Levels)

OpenCart shopping-cart file and directory paths expanded across all path depths, generated by Trickest from the OpenCart source tree. Useful for enumerating OpenCart admin models, catalog files and storefront structure.

ffufgobusterferoxbusterdirsearch
Details
Passwords39.1 MB
Openwall all (wordlists)

The merged all-languages Openwall wordlist, a large multilingual dictionary historically distributed by the Openwall/John the Ripper project.

johnhashcathydra
Web Content5.5 KB
OpenWrt LuCI Endpoints (SecLists)

OpenWrt LuCI web-interface admin endpoints (cgi-bin/luci/admin/*) for discovering and enumerating OpenWrt router management surfaces.

ffufgobusterferoxbuster
Details
Fuzzing1.6 KB
Operating system names

Operating system and distribution names for fuzzing user-agent, banner, and platform-identification parameters.

ffufwfuzzburpsuite
Details
Credentials10.2 KB
Oracle Better Default Passlist

Extensive list of default user:password combinations for Oracle Database, including SYSTEM and application-account defaults. Ideal for credential testing against Oracle TNS listeners.

hydramedusapatator
Details
Fuzzing7.7 KB
Oracle SQL Injection (FuzzDB)

Oracle-specific SQL injection payloads leveraging UTL_HTTP, UTL_INADDR out-of-band exfiltration and PL/SQL constructs. For probing Oracle DB back ends.

sqlmapburp
Details
Web Content7.2 KB
Oracle WebLogic Paths (SecLists)

Oracle WebLogic console, deployment, and servlet paths for enumerating WebLogic application servers and admin interfaces.

ffufgobusterferoxbuster
Details
Credentials7.1 KB
Phenoelit Default Password Database (user:pass)

The classic Phenoelit default-password database of vendor user:password pairs covering hundreds of networking and embedded devices. Long-standing reference set for default-credential testing.

hydramedusancrackpatator
Details
Fuzzing47.6 KB
PHP magic hashes

Magic-hash strings that evaluate as loose-equal in PHP type juggling, used to bypass weak == hash comparisons.

burpsuiteffufcustom-scripts
Details
Fuzzing165 B
PHP Magic Methods (SecLists)

PHP magic method names (__wakeup, __destruct, __toString, etc.) for PHP object injection / insecure deserialization gadget hunting and source-code review.

burpwfuzz
Details
Passwords184,388 lines (1.5 MB)
phpBB Leaked Passwords

Passwords from the phpBB forum breach. A solid mid-size real-world leak list for general cracking.

hashcatjohnhydra
Details
Web Content443 KB
phpBB Paths (All Levels)

phpBB forum software file and directory paths expanded across all path depths, generated by Trickest from the phpBB source tree. Useful for enumerating phpBB board files, config and administration paths.

ffufgobusterferoxbusterdirsearch
Details
Passwords9.5 MB
Polish Common Passwords

A roughly one-million-entry list of common Polish-language passwords, including Polish names and words like polska and misiek. Useful for cracking Polish-user accounts.

hashcatjohnhydramedusa
Details
Credentials124 B
Postgres Better Default Passlist

Default user:password combinations for PostgreSQL, covering common postgres and admin account defaults. Drop-in for credential testing against exposed Postgres services.

hydramedusapatator
Details
Fuzzing693 B
PostgreSQL Enumeration (FuzzDB)

PostgreSQL information-disclosure SELECT statements for enumerating version, current user/database and server settings once injection is confirmed. Useful post-detection on Postgres back ends.

sqlmapburp
Details
Web Content3.6 MB
PrestaShop Paths (All Levels)

Comprehensive PrestaShop e-commerce file and directory paths expanded across all path depths, generated by Trickest from the PrestaShop source tree. Useful for fingerprinting and enumerating PrestaShop installations and admin controllers.

ffufgobusterferoxbusterdirsearch
Details
Passwords12,645 lines (98 KB)
Probable Wordlists v2 – Top 12000

Sample from Berzerk0's Probable-Wordlists project, ordered by real-world frequency. Use as an efficient mid-size general-purpose list.

hashcatjohnhydra
Details
Passwords12.0 KB
Probable Wordlists v2 Top 1,575

The top 1,575 entries from the Probable-Wordlists v2 frequency-ranked dataset. A fast, high-hit-rate tier for online guessing and quick offline runs.

hashcatjohnhydramedusa
Details
Web Content6.2 KB
Pulse Secure VPN Paths (SecLists)

Pulse Secure / Ivanti Connect Secure VPN endpoints (dana-admin, dana-na, hc.cgi) for enumerating Pulse Secure appliances.

ffufgobusterferoxbuster
Details
Passwords809.1 KB
Pwdb Top 100,000 Passwords

The top 100,000 passwords from the Pwdb aggregated leak dataset, ranked by frequency. A solid mid-size general-purpose cracking list.

hashcatjohnhydra
Details
Passwords10,000 lines (79 KB)
Pwdb Top 10000

Top 10,000 entries from the Pwdb (passwords database) project, ranked by occurrence across many breaches. Strong general list.

hashcatjohnhydra
Details
Fuzzing77 lines (1 KB)
Quick SQLi Payloads

A short, high-signal set of SQL injection test strings (quotes, OR-based auth bypasses). Use for a fast first-pass SQLi check on input parameters and login forms.

ffufwfuzz
Details
Web Content2,567 lines (39 KB)
Quickhits

A curated list of high-signal paths likely to reveal sensitive files such as dotfiles, backups, config files, and admin panels. Great for a rapid, high-value first pass.

ffufgobusterferoxbusterdirsearch
Details
Web Content62,281 lines (529 KB)
RAFT Large Directories

RAFT-project directory names ranked by frequency from real web crawls. Excellent for discovering app directories (CMS, admin, framework paths) during web enumeration.

ffufgobusterferoxbusterwfuzz
Details
Web Content37,050 lines (482 KB)
RAFT Large Files

RAFT-project filenames ranked by frequency, including script and config files. Pair with an extension filter to hunt for specific files (login.php, xmlrpc.php, etc.) on a target.

ffufgobusterferoxbusterwfuzz
Details
Web Content29,999 lines (245 KB)
RAFT Medium Directories

Frequency-ranked directory names from the RAFT project, with broader coverage than the small list. A balanced choice for thorough directory brute-forcing.

ffufgobusterferoxbusterdirsearch
Details
Web Content17,129 lines (219 KB)
RAFT Medium Files

Frequency-ranked file names from the RAFT project with broader coverage than the small list. Good for enumerating files when directories are already known.

ffufgobusterferoxbusterdirsearch
Details
Web Content63,088 lines (512 KB)
RAFT Medium Words

Frequency-ranked raw words from the RAFT project with broader coverage, designed for fuzzing with user-supplied extensions for both files and directories.

ffufgobusterferoxbusterwfuzz
Details
Web Content20,115 lines (159 KB)
RAFT Small Directories

Frequency-ranked list of directory names derived from the RAFT research project. The small variant prioritizes the most common directories for quick discovery sweeps.

ffufgobusterferoxbusterdirsearch
Details
Web Content11,424 lines (145 KB)
RAFT Small Files

Frequency-ranked list of file names (with extensions) from the RAFT project. The small variant focuses on the most common files for fast content discovery.

ffufgobusterferoxbusterdirsearch
Details
Web Content43,007 lines (340 KB)
RAFT Small Words

Frequency-ranked raw words (no fixed extension) from the RAFT project, ideal for fuzzing both files and directories with custom extensions appended.

ffufgobusterferoxbusterwfuzz
Details
Fuzzing1.5 KB
Regional country codes

ISO-style country codes for fuzzing locale, region, and country parameters in web applications and APIs.

ffufwfuzzburpsuite
Details
Web Content195,167 lines (6.1 MB)
Robots Disallowed Top 10000

Paths harvested from Disallow directives across the most popular sites' robots.txt files, ranked by frequency. These paths often point to sensitive or interesting content site owners intended to hide.

ffufgobusterferoxbusterdirsearch
Details
Passwords30,289 lines (239 KB)
RockYou 65% Subset

A larger RockYou subset (65% frequency tier) with broader coverage than rockyou-50 while staying far smaller than the full list.

hashcatjohnhydra
Details
Passwords59,186 lines (468 KB)
RockYou-75 (75-char filtered)

A trimmed subset of the classic RockYou breach list (entries up to 75 chars). The go-to starter password list for offline hash cracking and credential brute-forcing when the full rockyou.txt is too large.

hashcatjohnhydramedusa
Details
Web Content97 KB
Roundcube Webmail Paths

File and directory paths from the Roundcube 1.2.3 webmail application, covering bin scripts, config, plugins and skins. Useful for fingerprinting and enumerating Roundcube webmail installations.

ffufgobusterferoxbusterdirsearch
Details
Web Content2.7 KB
Ruby on Rails Paths

Common Ruby on Rails application file and directory paths (Gemfile, Rakefile, app/controllers, config, sign-in endpoints). Useful for fingerprinting Rails apps and locating exposed framework files.

ffufgobusterferoxbusterdirsearch
Details
Passwords1 KB
Russian Common Passwords (Top 150)

The 150 most common Russian-user passwords from the Pwdb dataset, including keyboard walks adapted to Russian keyboards. A fast quick-hit list for Russian targets.

hashcatjohnhydramedusa
Details
API & Endpoints23.8 KB
Salesforce Aura objects

Salesforce Aura/Lightning object names for enumerating exposed Aura endpoints and probing object-level access controls.

ffufburpsuitegobuster
Details
Usernames204 B
SAP Default Usernames

Standard SAP service and administrative account names (DDIC, SAP*, EARLYWATCH, etc.) shipped with SAP systems. Ideal for targeting SAP NetWeaver and related enterprise deployments.

hydramedusapatator
Details
Web Content31 KB
SAP NetWeaver Paths

SAP NetWeaver web application paths and service endpoints (Adobe Document Services, config and WSDL endpoints). Useful for enumerating exposed SAP NetWeaver Java services and admin interfaces.

ffufgobusterferoxbusterdirsearch
Details
Credentials19.5 KB
SCADA Default Passwords (StrangeLove)

SCADA StrangeLove list of default and hardcoded credentials for ICS/SCADA devices (PLCs, controllers, industrial routers), with vendor, device, port and source columns. Reference and credential source for industrial-control assessments.

hydramedusapatator
Details
Passwords5,390 lines (55 KB)
Seasonal Password Patterns

Season-based passwords (Spring/Summer/Fall/Winter) with leet and suffix variations. Highly effective against corporate 90-day rotation passwords.

hashcatjohnhydra
Details
Web Content20,481 lines (163 KB)
SecLists Big Web Content

The dirb 'big' list, a larger alphabetically-sorted set of web paths. Use for more comprehensive content discovery than common.txt without the heavy size of directory-list-2.3-medium.

ffufgobusterferoxbusterdirb
Details
Web Content1.1 MB
SecLists combined_directories

SecLists' de-duplicated merge of many directory wordlists into a single ordered directory-discovery list. A strong general-purpose directory brute-force list.

ffufgobusterferoxbuster
Web Content1.1 MB
SecLists combined_words

SecLists' merged and de-duplicated wordlist of file/word entries (including dotfiles and VCS paths) for content discovery against web servers.

ffufgobusterferoxbusterwfuzz
Web Content4,751 lines (38 KB)
SecLists Common Web Content

The classic dirb 'common' list of frequently found web files and directories. The standard quick-pass wordlist for initial web content discovery on any target.

ffufgobusterdirbferoxbuster
Details
Subdomains151,265 lines (1.5 MB)
SecLists DNS Namelist

A large general-purpose DNS subdomain wordlist (the classic fierce/DNS brute namelist). Use for exhaustive subdomain enumeration when the top-5000 list is not enough.

ffufgobusterwfuzz
Details
Subdomains25.3 MB
SecLists dns-Jhaddix (all.txt)

Jason Haddix's massive all.txt subdomain brute-force wordlist, a classic for DNS enumeration and recon during bug bounty work. Contains millions of candidate subdomain labels.

amassdnsxpurednsffuf
Usernames10,735 lines (73 KB)
SecLists First Names

A large list of human first names, useful for generating or guessing username accounts. Use when targets use firstname-based logins or for building username permutations.

hydramedusaffufwfuzz
Details
Web Content52 KB
SecLists SVNDigger All Directories

Directory names mined from real-world source repositories by the SVNDigger project, covering frameworks, CMS internals and common app folders. A high-signal directory discovery list.

ffufgobusterferoxbusterdirb
Details
Web Content690 KB
SecLists SVNDigger All Files and Dirs

Comprehensive SVNDigger wordlist of file and directory names harvested from public source repositories. A large, real-world web content discovery list spanning many languages and frameworks.

ffufgobusterferoxbuster
Details
Usernames17 lines (111 B)
SecLists Top Usernames Shortlist

A tiny, high-value list of the most common service and admin usernames. Perfect as the username side of a credential brute-force or password spray against SSH, FTP, and web logins.

hydramedusaffufwfuzz
Details
Subdomains10.2 KB
Services Names

A focused 1,419-entry list of common service- and application-oriented subdomain names (api, graphql, admin, staging, etc.). Ideal for quickly surfacing modern app and API hosts.

ffufgobusterdnsx
Details
Web Content1,706 lines (41 KB)
SharePoint Web Content

Microsoft SharePoint-specific paths including _layouts, _catalogs, and _admin endpoints. Targeted for enumerating SharePoint deployments.

ffufgobusterferoxbusterdirsearch
Details
Subdomains723.9 KB
Shubs StackOverflow Subdomains

A 64,721-entry subdomain wordlist by Shubham Shah derived from StackOverflow data, rich in user- and project-style host names. Useful for catching unconventional, human-generated subdomains.

ffufgobusterpurednsdnsx
Details
Subdomains5.7 MB
Shubs Subdomains

Shubham Shah's (assetnote) curated 484,699-entry subdomain wordlist built from bug-bounty resolution data. A go-to list for deep, real-world subdomain discovery.

ffufpurednsamassdnsx
Details
Passwords92.5 KB
Singles.org Leaked Passwords

Plaintext passwords from the breach of the Christian dating site singles.org, heavy on faith-themed words. Great for themed password cracking and dictionary attacks.

hashcatjohnhydra
Details
Credentials22.2 KB
SNMP Community Strings (onesixtyone)

The onesixtyone-formatted variant of the large SecLists SNMP community-string list, ready to feed directly into the onesixtyone scanner.

onesixtyonesnmpwalk
Details
Credentials22.2 KB
SNMP Community Strings (snmp.txt)

The comprehensive SecLists SNMP community-string wordlist (~3,200 entries) for guessing read/write community strings on SNMP-enabled devices.

onesixtyonesnmpwalk
Details
Passwords5.8 MB
Spanish Common Usernames and Passwords

A large combined list of common Spanish-language usernames and passwords. Useful for credential-spraying Spanish and Latin American accounts.

hashcatjohnhydramedusa
Details
Fuzzing64 B
Special Characters

A minimal one-per-line list of special/punctuation characters for single-character injection and boundary fuzzing. Useful for quickly probing which metacharacters a field rejects or mishandles.

wfuzzburpffuf
Details
Web Content3.6 KB
Spring Boot Actuator Paths (SecLists)

Spring Boot Actuator endpoints (env, heapdump, beans, mappings, health) for enumerating exposed actuator interfaces on Java apps.

ffufgobusterferoxbuster
Details
Fuzzing2.9 KB
SQLi Generic Error-Based Payloads

Generic error-based SQL injection probe strings (OR/AND boolean conditions, HAVING, quote-escaping) used to trigger and detect SQL errors across DB engines.

sqlmapffufwfuzzburp
Details
Fuzzing354 B
SQLi Polyglots (SecLists)

Compact SQL injection polyglot payloads that trigger in multiple contexts (single/double quote, time-based) across MySQL with a single string.

sqlmapburpwfuzz
Details
Passwords136 lines (2 KB)
SSH Default Credentials (user:pass)

Common SSH default credentials in user:pass form. Feed directly to tools that accept combined credential lists for SSH brute-forcing.

hydramedusancrack
Details
Fuzzing3.4 KB
SSI / ESI Injection (PayloadsAllTheThings)

Server-Side Includes (SSI) and Edge-Side Includes (ESI) injection payloads using #echo, #config, #exec directives for variable disclosure and command execution.

burpwfuzznuclei
Details
Fuzzing7.8 KB
SSTI Fuzzing (PayloadsAllTheThings)

Server-Side Template Injection probes for many engines (Jinja2, Twig, Freemarker, ERB, Velocity and more), from simple math markers to object-introspection chains. For detecting and exploiting template injection.

wfuzzburpffuf
Details
Subdomains54.6 KB
Subdomains Spanish

A 5,370-entry list of Spanish-language subdomain labels for targeting Spanish and Latin American infrastructure. A useful regional supplement to English-centric lists.

ffufgobusterdnsx
Details
Subdomains1.3 MB
Subdomains Top 1 Million - 110000

The 110,000 most common subdomain labels from the Rapid7 Sonar 'top 1 million' DNS dataset. A deeper enumeration list that balances coverage and runtime.

ffufgobusteramasspuredns
Details
Subdomains132.4 KB
Subdomains Top 1 Million - 20000

The 20,000 most common subdomain labels derived from the Rapid7 Sonar 'top 1 million' DNS dataset. A fast, high-signal list for everyday subdomain brute-forcing.

ffufgobusteramasspuredns
Details
Subdomains5,000 lines (29 KB)
Subdomains Top 1 Million (5000)

The 5,000 most common subdomain labels derived from a million-entry corpus. The default fast list for DNS subdomain brute-forcing (gobuster dns / ffuf vhost).

ffufgobusterwfuzz
Details
Subdomains1.74 MB
Sublist3r subbrute Names

The large subbrute names list (~129k entries) used by Sublist3r for DNS subdomain brute-forcing, suitable for comprehensive enumeration sweeps.

sublist3ramassdnsxpuredns
Details
API & Endpoints92.2 KB
Swagger / OpenAPI Paths (SecLists)

Swagger and OpenAPI documentation endpoints (api-docs, swagger-ui, openapi.json, _wadl) for discovering exposed API specs and UIs.

ffufgobusterferoxbuster
Details
Passwords1.1 KB
Swedish Common Passwords (Top 150)

Top 150 most common Swedish-language passwords from the Pwdb dataset. Useful for locale-aware credential attacks against Swedish targets.

hashcatjohnhydramedusa
Details
Web Content12 KB
Symfony 3.1.5 Demo Paths

File and directory paths from a Symfony 3.1.5 demo application, covering app config, kernel, cache and bundle layout. Useful for fingerprinting Symfony installations and locating exposed config files.

ffufgobusterferoxbusterdirsearch
Details
Credentials2.3 KB
Telnet Better Default Password List

Curated user:password default-credential pairs for Telnet-exposed devices and appliances. Ideal for spraying default logins against Telnet services on IoT and embedded gear.

hydramedusancrackpatator
Details
Credentials1.1 KB
Tomcat Better Default Passlist

Default user:password combinations for Apache Tomcat Manager and related admin accounts. Ideal for testing exposed Tomcat /manager interfaces with HTTP-auth brute-force tools.

hydramedusaffufwfuzz
Details
Passwords180 B
Top 20 Common SSH Passwords

The 20 passwords most frequently tried against SSH services by automated bots and scanners. Ideal for quick, low-noise online SSH brute-force checks.

hydramedusancrackpatator
Details
Subdomains29.0 KB
Top-Level Domains (SecLists)

A list of TLDs and public suffixes (each prefixed with a dot) for horizontal domain enumeration and TLD-sweeping across an organization's apex domains.

amassdnsxpurednsffuf
Details
Passwords1.2 KB
Turkish Common Passwords (Top 150)

Top 150 most common Turkish-language passwords from the Pwdb dataset. Useful for targeting Turkish users and locale-specific credential guessing.

hashcatjohnhydramedusa
Details
Passwords3 KB
Twitter Banned Passwords

The list of passwords Twitter banned from registration because they were deemed too common or weak. A compact, high-signal list of obvious passwords.

hashcatjohnhydramedusa
Details
Passwords1.2 KB
Ukrainian Common Passwords (Top 150)

Top 150 most common Ukrainian-language passwords from the Pwdb dataset. Useful for credential guessing against Ukrainian users.

hashcatjohnhydramedusa
Details
Web Content34 KB
Umbraco CMS Paths

File and directory paths for the Umbraco ASP.NET CMS, including config files, backoffice and umbraco directories. Useful for fingerprinting and enumerating Umbraco installations.

ffufgobusterferoxbusterdirsearch
Details
Fuzzing458 KB
Unicode Fuzzing Strings (SecLists)

Exhaustive list of URL-encoded byte/Unicode code points (%00%00 through the full range), for fuzzing control characters, null bytes, and encoding-handling edge cases.

ffufwfuzzburp
Details
Fuzzing13 KB
Unix Attack Fuzz Strings (FuzzDB)

Wide sample of malicious input for Unix-like targets mixing SQLi quote breakers, format strings, XXE and command-injection vectors from FuzzDB.

wfuzzffufburp
Details
Fuzzing1.2 KB
Unix Command Execution Injection

Unix OS command-injection payloads using pipes, semicolons, backticks and SSI exec to run id/cat/netstat on vulnerable parameters.

wfuzzffufburp
Details
Fuzzing1.0 KB
URL-Encoded Hex Bytes (Single)

All 256 byte values single-URL-encoded (%xx), including the null byte %00, for null-byte injection, encoding fuzzing and input-handling tests.

ffufwfuzzburp
Details
Passwords202.2 KB
US cities list

List of US city names useful for location-based security-question answers, password seeds, and geographic enumeration.

hydraburpsuiteffuf
Details
Fuzzing108 KB
User-Agents Fuzzing List

A large collection of real User-Agent strings (browsers, bots, crawlers, tools) for fuzzing the User-Agent header to trigger different code paths or filter behaviour. Useful for header-based logic and access-control testing.

wfuzzburpffuf
Details
Web Content1.7 KB
Version Control Metafiles (SecLists)

Exposed version-control metadata files (.git, .svn, CVS, .bzr, .hg) used to detect leaked source-control directories on web roots.

ffufgobusterferoxbusterdirb
Details
Credentials330 B
VNC Better Default Password List

Default VNC passwords harvested from embedded systems and appliances (VNC auth is password-only, no username). Suited for VNC default-credential checks.

hydramedusancrackpatator
Details
Web Content43 lines (227 B)
Web Extensions

Short list of common web file extensions (.php, .asp, .aspx, .jsp, .html, etc.) intended to be appended to word-based wordlists during fuzzing.

ffufgobusterferoxbusterdirsearch
Details
Web Content14.4 KB
Web shell / backdoor filenames

Known web shell and backdoor filenames for discovering attacker-dropped scripts left on compromised web servers.

ffufgobusterferoxbuster
Details
Fuzzing13 KB
Windows Attack Fuzz Strings (FuzzDB)

Wide sample of malicious input for Windows targets: command-injection metachars, boundary integers and OS-specific attack vectors from FuzzDB.

wfuzzffufburp
Details
Web Content1,578 lines (58 KB)
WordPress Fuzz

WordPress core paths and files (wp-admin, wp-includes, installer scripts, readme/license). Ideal for enumerating WordPress installations.

ffufgobusterferoxbusterwfuzz
Details
Web Content13,370 lines (493 KB)
WordPress Plugins Fuzz

Extensive list of WordPress plugin directory paths under wp-content/plugins/. Use to fingerprint installed plugins and find vulnerable or outdated extensions.

ffufgobusterferoxbusterwfuzz
Details
Web Content112 KB
WordPress Themes Fuzz

List of WordPress theme directory paths under wp-content/themes/. Useful for enumerating installed WordPress themes to fingerprint a site and find vulnerable theme versions.

ffufgobusterferoxbusterdirsearch
Details
Passwords1,000 lines (7 KB)
Xato Top 1,000 Passwords

The 1,000 most common passwords from Mark Burnett's 10-million-password corpus. Ideal for fast online login spraying with Hydra/Medusa where a tiny, high-hit list matters.

hydramedusahashcatjohn
Details
Passwords10,000 lines (75 KB)
Xato Top 10,000 Passwords

Top 10,000 real-world passwords ranked by frequency. A balanced default for both online brute-forcing and quick offline dictionary attacks.

hydramedusahashcatjohn
Details
Passwords100,000 lines (764 KB)
Xato Top 100,000 Passwords

Top 100,000 frequency-ranked passwords. A larger dictionary for thorough offline hash cracking when speed allows and you want broader coverage than the 10k list.

hashcatjohnhydramedusa
Details
Usernames81.3 MB
xato-net 10-million-usernames (full)

The full deduplicated xato.net 10-million usernames list extracted from the same breach corpus as the matching passwords list. The canonical large username wordlist for credential and login enumeration.

hydramedusa
Usernames4.9 MB
Xato-Net 10M Usernames (frequency-ordered, with duplicates)

Frequency-ordered version of Jordan Wright's Xato 10-million-username corpus, retaining duplicate weighting so the most statistically common usernames appear first. Excellent ordered seed list for username enumeration and credential-stuffing.

hydramedusancrackkerbrute
Details
Fuzzing8.0 KB
XML / SOAP Attack Payloads

XML/SOAP/XXE attack payloads: external SYSTEM entity file reads, RFI entities, XML-RPC methodCall structures and entity-expansion vectors.

burpnucleiwfuzz
Details
Fuzzing1.9 KB
XML / XXE Fuzzing Payloads

XML fuzzing payloads including CDATA XSS, SYSTEM entity (XXE) file disclosure and DOCTYPE injection vectors for XML parser testing.

burpwfuzznuclei
Details
Fuzzing1.2 KB
XSS event handlers (0xcela)

HTML event-handler attribute names (onmouseover, onerror, etc.) for fuzzing reflected and stored XSS injection points.

burpsuiteffufwfuzz
Details
Fuzzing184 KB
XSS PayloadBox List

The large payloadbox XSS payload collection mirrored in SecLists, with thousands of vectors and obfuscation variants. A high-coverage list for thorough XSS fuzzing.

wfuzzburpffuf
Details
Fuzzing110 lines (19 KB)
XSS Payloads (Jhaddix)

Jhaddix's robot-friendly cross-site scripting payload collection covering script tags, event handlers, and filter-bypass vectors. Inject into reflected parameters to fuzz for XSS.

ffufwfuzz
Details
Fuzzing1.6 KB
XSS Polyglots

Single-string XSS polyglots crafted to break out of and fire in many different HTML/JS/attribute contexts at once. Efficient when you can only inject one test value per field.

wfuzzburpffuf
Details
Fuzzing4.1 KB
XSS RSnake Cheat Sheet

The classic RSnake/ha.ckers.org XSS cheat sheet of vectors and filter-evasion encodings. A foundational list for cross-site scripting detection and bypass testing.

wfuzzburpffuf
Details
Fuzzing4.8 KB
XXE Fuzzing

XML External Entity payloads including DOCTYPE/ENTITY declarations for file disclosure via file:// and php://filter wrappers. For testing XML parsers for XXE.

wfuzzburp
Details
In-browser, private by default

Don't see your list? Generate one.

Hashcat-style masks, brute-force charsets, and word-mutation rules — generated entirely client-side and streamed straight to a download.

Open the generator