
cryptohackapp
The mobile engineering home of the Cryptohack Badge project.

The mobile engineering home of the Cryptohack Badge project.

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

Exploit for CVE-2025-64512 to get a reverse shell.

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

Gogs service Exploit and get the root user

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

Linux 内核升级指南 - 修复 CVE-2026-53359

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

PlaceOS authentication service and API gatekeeper.

OSINT Tool gets a range of information from an Instagram account 🛠

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Accurately Locate Smartphones using Social Engineering