5148 | Samsung Galaxy Apps MiTM vulnerabilities |
MiTM
Android |
Samsung |
Simone Margaritelli (@evilsocket) |
Bug Bounty | 2016-08-17 | 2023-06-13 |
4992 | Stealing 0Auth Token (MITM) |
OAuth |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-09-01 | 2023-06-13 |
4217 | Scary Bug in Burp Suite Upstream Proxy Allows Hackers to Hack Hackers |
MiTM |
PortSwigger |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-04-06 | 2023-06-13 |
4040 | 500$ bounty: Man in the Middle on Slack |
MiTM |
Slack |
Wiard van Rij / Sysrant (@RijWiard) |
Bug Bounty | 2019-07-15 | 2023-06-13 |
3965 | Kaspersky in the Middle – what could possibly go wrong? |
Clickjacking
Universal XSS
MiTM |
Kaspersky |
Wladimir Palant (@WPalant) |
Bug Bounty | 2019-08-19 | 2023-06-13 |
3732 | Update: Want to take over the Java ecosystem? All you need is a MITM! |
MiTM
Insecure communications |
Github |
Jonathan Leitschuh (@jlleitschuh) |
Bug Bounty | 2020-01-08 | 2023-06-13 |
3721 | The trouble with Microsoft’s Troubleshooters |
RCE
MiTM |
Microsoft |
Imre Rad (@ImreRad) |
Bug Bounty | 2020-01-15 | 2023-06-13 |
2799 | SHAREit Flaw Could Lead to Remote Code Execution |
Android
RCE
MiTM
Man-in-the-Disk attack
Insecure intent
Vulnerable Android content provider |
SHAREit |
Echo Duan |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2760 | Host MITM attack via IPv6 rogue router advertisements (K8S CVE-2020-10749 / Docker CVE-2020-13401 / LXD / WSL2 / ...) |
MiTM |
Kubernetes |
Etienne Champetier / champtar |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2759 | Kubernetes man in the middle using LoadBalancer or ExternalIPs (CVE-2020-8554) |
MiTM |
Kubernetes |
Etienne Champetier / champtar |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2743 | Content Injection (RCE) in Yandex Browser for Android [2018] |
MiTM |
Yandex |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2517 | Metadata service MITM allows root privilege escalation (EKS / GKE) |
Kubernetes
Privilege escalation
MiTM |
Google |
Etienne Champetier / champtar |
Bug Bounty | 2021-05-30 | 2023-06-13 |
2414 | Unencrypted HTTP Links to Google Scholar in Search |
MiTM |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2293 | Pwn2Own Vancouver 2021 :: Microsoft Exchange Server Remote Code Execution |
RCE
MiTM |
Microsoft |
Steven Seeley (@steventseeley) |
Bug Bounty | 2021-08-25 | 2023-06-13 |
2206 | Mama Always Told Me Not to Trust Strangers without Certificates |
MiTM
RCE |
Netgear |
Adam (@AdamOfDc949) |
Bug Bounty | 2021-09-21 | 2023-06-13 |
2153 | ESET Endpoint Security credentials theft |
Credentials sent over unencrypted channel
MiTM |
ESET |
Mehdi Alouache |
Bug Bounty | 2021-10-12 | 2023-06-13 |
1424 | CVE-2022-32208: FTP-KRB bad message verification |
MiTM |
Internet Bug Bounty (curl) |
Harry Sintonen |
Bug Bounty | 2022-06-27 | 2023-06-13 |
1301 | Vulnerability in Dahua’s ONVIF Implementation Threatens IP Camera Security |
MiTM |
Dahua |
Nozomi Networks Labs (@nozominetworks) |
Bug Bounty | 2022-07-28 | 2023-06-13 |
1249 | Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software |
RCE
OS command injection
Local Privilege Escalation
MiTM |
Cisco |
Jake Baines (@Junior_Baines) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1204 | Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets? |
Robotic Process Automation
Insecure deserialization
SQL injection
MiTM |
Blue Prism |
Nimrod Stoler (@n1mr0d5) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1107 | Baxter SIGMA Spectrum Infusion Pumps: Multiple Vulnerabilities (FIXED) |
Hardcoded credentials
Memory corruption
MiTM
Information disclosure |
Baxter Healthcare |
Deral Heiland (@Percent_X) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1080 | Security Advisory: NETGEAR Routers FunJSQ Vulnerabilities |
OS command injection
RCE
MiTM |
Netgear |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1027 | Layer 2 network security bypass using VLAN 0, LLC/SNAP headers and invalid length |
Layer 2 networking vulnerability
Ethernet
MiTM
DoS |
Microsoft
Cisco |
Etienne Champetier / champtar |
Bug Bounty | 2022-09-27 | 2023-06-13 |
898 | RC4 Is Still Considered Harmful |
Kerberos
MiTM
Local Privilege Escalation
Downgrade attack |
Microsoft (Windows) |
James Forshaw (@tiraniddo) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
466 | A tale of a full Business Takeover — Red Team Diaries |
MITM
Credential stuffing
Password spraying |
NA |
Dhanesh Dodia - HeyDanny (@Dhanesh_Dodia) |
Bug Bounty | 2023-02-11 | 2023-06-13 |