2871 | Bypassing WAF with incorrect proxy settings for Hunting Bugs. |
URL validation bypass |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2827 | Abusing URI Parsers for fun and profit |
URL validation bypass |
NA |
Mohammad Owais (@_mohammadowais) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2732 | Bypassing Chrome%27s URL restrictions |
Browser hacking
URL validation bypass |
Google (Chrome) |
Jeffrey Bencteux (@jeffbencteux) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2067 | URL whitelist bypass in https://cxl-services.appspot.com |
Privilege escalation
URL validation bypass
SSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
1886 | CVE-2020-0696 - Microsoft Outlook Security Feature Bypass Vulnerability |
URL validation bypass |
Microsoft |
Reegun Jayapaul (@reegun21) |
Bug Bounty | 2022-01-27 | 2023-06-13 |
764 | Multiple Vulnerabilities found in Airtel Android Application |
Arbitrary Code Execution
URL validation bypass
Symlink attack
XSS
Android
Webview |
Airtel
Google |
Gaurang Bhatnagar (@hax0rgb) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
732 | URL Validation Bypass Using Browser URI Normalization |
URL validation bypass |
NA |
Marx Chryz Del Mundo |
Bug Bounty | 2022-12-04 | 2023-06-13 |
594 | Bypassing authorization in Google Cloud Workstations [Google VRP] |
Account takeover
OAuth
URL validation bypass |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
563 | Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434) |
Android
Insecure intent
Insecure deeplink
URL validation bypass |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
286 | Remote code execution in BIRT Viewer ≤ 4.12.0 (CVE-2023-0100) |
RCE
RFI
URL validation bypass
Security code review |
Eclipse Foundation |
Louis Wolfers (@TG91aXMK) |
Bug Bounty | 2023-03-17 | 2023-06-13 |
172 | Bypassing Link Sharing Protection in Messenger Kids Parent’s Control Feature | Meta Bug Bounty |
URL validation bypass |
Meta / Facebook |
Syd Ricafort (@devsyd11) |
Bug Bounty | 2023-04-20 | 2023-06-13 |