4070 | Nuget/Squirrel uncontrolled endpoints leads to arbitrary code execution |
RCE |
Microsoft |
Reegun J (@reegun21) |
Bug Bounty | 2019-06-28 | 2023-06-13 |
3185 | Oversecured automatically discovers persistent code execution in the Google Play Core Library |
Arbitrary Code Execution
Android |
Google |
Oversecured (@OversecuredInc) |
Bug Bounty | 2020-08-28 | 2023-06-13 |
3122 | Arbitrary code execution on Facebook for Android through download feature |
Arbitrary code execution |
Meta / Facebook |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2020-10-02 | 2023-06-13 |
2640 | Allow arbitrary URLs, expect arbitrary code execution |
RCE |
Nextcloud
Telegram
VLC |
Fabian Bräunlein |
Bug Bounty | 2021-04-15 | 2023-06-13 |
2581 | ExifTool CVE-2021-22204 - Arbitrary Code Execution |
RCE |
GitLab |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2021-05-04 | 2023-06-13 |
1106 | Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution |
Arbitrary Code Execution
Local Privilege Escalation |
AVEVA |
Daan Keuper (@daankeuper) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1088 | Hacking Unity Games with Malicious GameObjects |
Arbitrary code execution
RCE |
Unity |
Jason Kielpinski (@f2jason) |
Bug Bounty | 2022-09-13 | 2023-06-13 |
948 | Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution |
RCE |
ICONICS |
Sector 7 (@sector7_nl) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
764 | Multiple Vulnerabilities found in Airtel Android Application |
Arbitrary Code Execution
URL validation bypass
Symlink attack
XSS
Android
Webview |
Airtel
Google |
Gaurang Bhatnagar (@hax0rgb) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
220 | A web security story from 2008: silently securing JSON.parse |
Parsing issue
XSS
Arbitrary Code Execution |
JSON.parse |
Mike Samuel (@mvsamuel) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
152 | Git Arbitrary Configuration Injection (CVE-2023-29007) |
Logic flaw
Arbitrary Code Execution
Security code review |
Git |
André Baptista (@0xacb) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
151 | Alias file to rule them all — One click code execution with alias file in macOS |
Arbitrary Code Execution
TCC bypass |
Apple (macOS) |
Mikko Kenttälä (@Turmio_) |
Bug Bounty | 2023-04-26 | 2023-06-13 |