Skip to content

Pull requests: HackTricks-wiki/hacktricks

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Unauthenticated File Upload in Amasty Order Attributes for M...
#2382 opened Jun 16, 2026 by carlospolop Collaborator Loading…
SearchLeak How We Turned M365 Copilot Into a One-Click Data ...
#2380 opened Jun 15, 2026 by carlospolop Collaborator Loading…
Burp Suite Professional browser-powered crawler file input p...
#2377 opened Jun 15, 2026 by carlospolop Collaborator Loading…
MeshCentral From Agent-Controlled Stored XSS to Fleet-Wide R...
#2376 opened Jun 14, 2026 by carlospolop Collaborator Loading…
I Accidentally Logged in as Admin to a Threat Actor Website
#2375 opened Jun 14, 2026 by carlospolop Collaborator Loading…
Sleeping Beauty II CFG, CET, and Stack Spoofing
#2373 opened Jun 14, 2026 by carlospolop Collaborator Loading…
Client-side Authentication Bypass
#2371 opened Jun 14, 2026 by carlospolop Collaborator Loading…
HackTheBox VariaType Exposed Git, Traversal Filter Bypass, f...
#2370 opened Jun 13, 2026 by carlospolop Collaborator Loading…
Factoring “short-sleeve” RSA keys with polynomials
#2366 opened Jun 12, 2026 by carlospolop Collaborator Loading…
JS-Tap v3 Endpoint Post-Exploitation With JavaScript Implant...
#2365 opened Jun 12, 2026 by carlospolop Collaborator Loading…
Visa Vulnerability Agentic Harness — Agentic SAST Pipeline
#2362 opened Jun 11, 2026 by carlospolop Collaborator Loading…
From SQLi to RCE Exploiting LangGraph's Checkpointer
#2361 opened Jun 11, 2026 by carlospolop Collaborator Loading…
Oops, I Weaponized the Database Abusing AI Features in SQL S...
#2359 opened Jun 11, 2026 by carlospolop Collaborator Loading…
Pre-authentication XXE to OOB SSRF in HPE ArubaOS 8.13.2.0 X...
#2358 opened Jun 10, 2026 by carlospolop Collaborator Loading…
More Evidence That Words Don’t Mean What We Thought They Mea...
#2357 opened Jun 10, 2026 by carlospolop Collaborator Loading…
CVE-2026-10520 and CVE-2026-10523 Multiple Critical Vulnerab...
#2356 opened Jun 10, 2026 by carlospolop Collaborator Loading…
Advanced Evasion Tradecraft Precision Module Stomping
#2354 opened Jun 9, 2026 by carlospolop Collaborator Loading…
How I Found a Critical OAuth Misconfiguration That Led to Ac...
#2353 opened Jun 9, 2026 by carlospolop Collaborator Loading…
SearchJack 23 Chrome Extensions Silently Monetize ~758,000 U...
#2350 opened Jun 9, 2026 by carlospolop Collaborator Loading…
ISO 8583 Under Fire Finding Vulnerabilities in a Payment Soc...
#2349 opened Jun 9, 2026 by carlospolop Collaborator Loading…
NFCShare evolves from a banking phishing APK to a GitHub-hos...
#2347 opened Jun 9, 2026 by carlospolop Collaborator Loading…
HTB Facts Camaleon CMS Mass Assignment, MinIO Credential Piv...
#2342 opened Jun 6, 2026 by carlospolop Collaborator Loading…
Popping Root on UniFi OS Server Unauthenticated RCE Chain De...
#2339 opened Jun 6, 2026 by carlospolop Collaborator Loading…
Pwnd Blaster Hacking Your PC Using Your Speaker Without Ever...
#2337 opened Jun 5, 2026 by carlospolop Collaborator Loading…
Bypassing SSL Pinning on Play Store AVDs without Frida
#2336 opened Jun 5, 2026 by carlospolop Collaborator Loading…
ProTip! Follow long discussions with comments:>50.