4464 | From Security Misconfiguration to Gaining Access of SMTP server |
File disclosure |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2018-11-18 | 2023-06-13 |
3565 | Hundreds of internal servicedesks exposed due to COVID-19 |
Security misconfiguration |
NA |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3532 | Misconfigured WordPress takeover to Remote Code Execution |
Wordpress takeover
RCE
Security misconfiguration |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3312 | How I hacked into a Telecom Network |
RCE
Security misconfiguration
JBoss |
NA |
Harpreet Singh |
Bug Bounty | 2020-07-11 | 2023-06-13 |
1980 | NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories |
Security misconfiguration
.git folder disclosure |
Microsoft |
Wiz (@wiz_io) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1842 | Google Security Misconfiguration Leads to Account Takeover ! |
Logic flaw
Spoofing |
Google |
Harsh Banshpal |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1039 | Complete take-over of Cisco Unified Communications Manager due consecutively misconfigurations |
Security misconfiguration
VoIP hacking |
NA |
hackthebox |
Bug Bounty | 2022-09-24 | 2023-06-13 |
942 | The Danger of Falling to System Role in AWS SDK Client |
Cloud
Privilege escalation
Security misconfiguration |
NA |
Fracensco Lacerenza (@lacerenza_fra) |
Bug Bounty | 2022-10-18 | 2023-06-13 |
804 | System misconfiguration is the number one vulnerability, at least for Mastodon |
Security misconfiguration
MinIO misconfiguration |
infosec.exchange |
Lenin Alevski (@Alevsk) |
Bug Bounty | 2022-11-19 | 2023-06-13 |
798 | Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs |
GraphQL
Security misconfiguration |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
785 | Dodging OAuth origin restrictions for Firebase spelunking |
OAuth
Security misconfiguration
Authentication flaw |
NA |
Aditya Saligrama (@saligrama_a) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
767 | Firebase Exploit bug bounty |
Security misconfiguration
Firebase |
NA |
Damaidec |
Bug Bounty | 2022-11-27 | 2023-06-13 |
570 | API Misconfiguration - No Swag of SwaggerUI |
Security misconfiguration
Privilege escalation |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
501 | Azure security — Internal recon leveraging lack of access control |
Azure AD
Cloud
Security misconfiguration
Privilege escalation |
Microsoft (Azure) |
Molx32 |
Bug Bounty | 2023-02-02 | 2023-06-13 |
494 | How we made $120k bug bounty in a year with good automation |
XSS
Security misconfiguration
Log4shell
Debug mode enabled |
NA |
Dawid Moczadło (@kannthu1) |
Bug Bounty | 2023-02-06 | 2023-06-13 |
458 | Hacking our way into internal DBs with hardcoded authentication keys |
JWT
SSO
Authentication bypass
Security misconfiguration |
NA |
Ophion Security (@OphionSecurity) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
439 | Hacking Apple: Two Successful Exploits and Positive Thoughts on their Bug Bounty Program |
RCE
Security misconfiguration |
Apple |
Joe Gregg (@infiltrateops) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
425 | Multiple vulnerabilities in Nokia BTS Airscale ASIKA |
Base transceiver station
Path traversal
Hardcoded private key
Local Privilege Escalation
Security misconfiguration |
Nokia |
Geoffrey Bertoli (@YofBalibump) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
308 | Microsoft Defender for Cloud Management Port Exposure Confusion |
Cloud
Security misconfiguration |
Microsoft |
Aaron Sawitsky |
Bug Bounty | 2023-03-14 | 2023-06-13 |
199 | How I got RCE in + 10 websites… |
RCE
Security misconfiguration |
NA |
m4cddr (@m4cddr) |
Bug Bounty | 2023-04-13 | 2023-06-13 |
166 | Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers |
Salesforce
Security misconfiguration
Broken Access Control |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2023-04-21 | 2023-06-13 |
161 | No Portals Needed |
MFA bypass
Security misconfiguration |
NA |
Chen Levy Ben Aroy |
Bug Bounty | 2023-04-24 | 2023-06-13 |
78 | A $1,000,000 bounty? The KuCoin User Information Leak |
Information disclosure
Zendesk
Authorization flaw
Security misconfiguration |
NA |
Corben Leo (@hacker_) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
68 | AEM Bug in Adobe |
AEM
Missing authentication
Security misconfiguration |
Adobe |
Muhammad Mater (@micro0x00) |
Bug Bounty | 2023-05-20 | 2023-06-13 |
38 | Ghost Sites: Stealing Data From Deactivated Salesforce Communities |
Salesforce
Security misconfiguration |
NA |
Nitay Bachrach |
Bug Bounty | 2023-05-31 | 2023-06-13 |