Skip to main content
Free Download — No Signup

Security Wordlists

Curated wordlists for bug bounty hunting and penetration testing. Subdomain enumeration, directory discovery, password lists, and fuzzing payloads — all free to download.

Subdomain Enumeration

Top 1M Subdomains

Most comprehensive subdomain wordlist for DNS brute-force

1,000,000 entries15MBSource: SecLists
Download

Common Subdomains

Fast scan — top 100 most common subdomains

100 entries2KBSource: CyberMind
Download

Bug Bounty Subdomains

Optimized for bug bounty programs

50,000 entries500KBSource: SecLists
Download

Directory & File Discovery

Common Web Paths

Medium-sized directory list for web app testing

220,000 entries1MBSource: SecLists
Download

API Endpoints

Common REST API endpoint names

3,000 entries50KBSource: SecLists
Download

Backup Files

Backup file extensions and names

500 entries10KBSource: SecLists
Download

Admin Panels

Common admin panel paths

300 entries5KBSource: SecLists
Download

Password Lists

Top 10,000 Passwords

Most common passwords for credential testing

10,000 entries80KBSource: SecLists
Download

Default Credentials

Default username/password combinations for devices

1,000 entries20KBSource: SecLists
Download

Fuzzing & Payloads

XSS Payloads

XSS payloads for reflected/stored XSS testing

2,000 entries30KBSource: SecLists
Download

SQLi Payloads

Generic SQL injection payloads

1,000 entries20KBSource: SecLists
Download

SSRF Payloads

SSRF bypass payloads for internal network access

200 entries5KBSource: SecLists
Download

LFI Payloads

Local file inclusion traversal payloads

500 entries10KBSource: SecLists
Download

Use Wordlists with CyberMind CLI

CyberMind CLI auto-generates target-specific wordlists using AI. No manual download needed.

cybermind /wordlist login-page cybermind /wordlist api-endpoints cybermind /wordlist admin-panel