2544 | DOS & Stored HTML Injection Bug Bounty Writeup |
DoS
HTML injection |
NA |
RiotSecurityTeam (@RiotSecTeam) |
Bug Bounty | 2021-05-19 | 2023-06-13 |
1941 | thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality |
IDOR
Password reset
Account takeover |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2022-01-04 | 2023-06-13 |
1691 | Pwning Microsoft Azure Defender for IoT | Multiple Flaws Allow Remote Code Execution for All |
RCE
Memory corruption
SQL injection |
Microsoft |
Kasif Dekel (@kasifdekel) |
Bug Bounty | 2022-03-28 | 2023-06-13 |
1631 | Inside the Black Box | How We Fuzzed Microsoft Defender for IoT and Found Multiple Vulnerabilities |
DoS
Memory corruption |
Microsoft |
Kasif Dekel (@kasifdekel) |
Bug Bounty | 2022-04-13 | 2023-06-13 |
1338 | Riding The Inforail To Exploit Ivanti Avalanche |
RCE
Insecure deserialization
Race condition
Authentication bypass |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1151 | HTMLI/XSS - Crafting a better PoC |
XSS
HTML injection |
NA |
RiotSecurityTeam (@RiotSecTeam) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1100 | Riding The Inforail To Exploit Ivanti Avalanche Part 2 |
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
1014 | Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned) |
Web cache poisoning |
Akamai
Paypal
Airbnb
Tesla
Valve
Zomato
Whitejar
Starbucks
PlayStation
Marriott
Hyatt Hotels
Goldman Sachs
Microsoft
Apple
LastPass
Brussels Airlines
Mastercard
eToro BBP
BMW Group
Rockstar Games |
Francesco Mariani (@_medusa_1_) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
884 | Vulnerabilities In Apache Batik Default Security Controls – SSRF And RCE Through Remote Class Loading |
SSRF
RCE |
Apache Batik |
Piotr Bazydło (@chudypb) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
823 | Control Your Types Or Get Pwned: Remote Code Execution In Exchange Powershell Backend |
RCE
Windows |
Checkmk |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2022-11-16 | 2023-06-13 |
801 | Hacking Smartwatches for Spear Phishing |
IoT
Phishing
Android |
NA |
Cybervelia (@cybervelia) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
781 | Legally hacking a Government Satellite? |
Missing authentication
OS command injection
RCE |
NA |
RiotSecTeam (@RiotSecTeam) |
Bug Bounty | 2022-11-24 | 2023-06-13 |
769 | Automating Unsolicited Richard Pics; Pwning 60,000 Digital Picture Frames |
IDOR
Broken Access Control
Android
IoT |
Ourphoto |
Nick M (@1oopho1e) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
760 | discord.exe – Improper Input Validation |
Security code review
Local Privilege Escalation
Phishing |
Discord |
RiotSecTeam (@RiotSecTeam) |
Bug Bounty | 2022-11-28 | 2023-06-13 |
751 | XSS on account.leagueoflegends.com via easyXDM [2016] |
XSS
postMessage |
Riot Games |
Luke Young (@TheBoredEng) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
647 | Turning Google smart speakers into wiretaps for $100k |
IoT
Wifi hacking |
Google |
Matt |
Bug Bounty | 2022-12-26 | 2023-06-13 |
588 | thisclosed_#2 - PostgreSQL Database Exfiltration through the abuse of PostgREST requests |
SQL injection |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2023-01-16 | 2023-06-13 |
559 | Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP” |
Kernel hacking
Windows
RCE
Memory corruption
Buffer Overflow |
Microsoft (Windows) |
Valentina Palmiotti (@chompie1337) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
479 | Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization |
Insecure deserialization
RCE
Security code review |
Inductive Automation Ignition |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
378 | CVE-2022-38108: RCE In Solarwinds Network Performance Monitor |
Insecure deserialization
RCE
Security code review |
SolarWinds |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
328 | The Silent Spy Among Us: Modern Attacks Against Smart Intercoms |
IoT
OS command injection
Missing authentication
MiTM
SIP |
Akuvox |
Claroty%27s Team82 (@Claroty) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
326 | Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation) |
Local Privilege Escalation
IoT |
NA |
Sean Pesce (@SeanPesce) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
165 | Compromising Garmin’s Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine |
IoT
Memory corruption
Buffer Overflow
Integer overflow
Out-of-bounds Read
Out-of-bounds Write
Type confusion
Permission bypass
Reverse engineering |
Garmin |
Tao Sauvage |
Bug Bounty | 2023-04-21 | 2023-06-13 |
109 | PwnAssistant - Controlling /home%27s Via A Home Assistant RCE |
Authentication bypass
RCE
Security code review
IoT |
Home Assistant |
elttam (@elttam) |
Bug Bounty | 2023-05-09 | 2023-06-13 |