5234 | Google Bug Bounty: Nice Catch on Google Cloud Platform Live |
Reflected XSS |
Google |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2014-11-20 | 2023-06-13 |
5208 | Open Redirect in Linkedin and Yahoo |
Open redirect |
LinkedIn
Yahoo! / Verizon Media |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2015-09-24 | 2023-06-13 |
5163 | Uber Hacking: How we found out who you are, where you are and where you went |
Bruteforce
Information disclosure
Logic flaw
IDOR |
Uber |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2016-06-24 | 2023-06-13 |
5155 | Remote Code Execution (RCE) on Microsoft%27s %27signout.live.com%27 |
RCE |
Microsoft |
Peter Adkins (@darkarnium) |
Bug Bounty | 2016-07-24 | 2023-06-13 |
5091 | Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat |
Open redirect
SSRF
Path traversal |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-09 | 2023-06-13 |
5085 | Near universal XSS in McAfee Web Gateway |
XSS |
McAfee |
Olivier Arteau |
Bug Bounty | 2017-03-17 | 2023-06-13 |
4963 | Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.co |
Subdomain takeover |
Lamborghini |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4805 | How I hacked companies related to the crypto currency and earned $60,000 |
Authorization flaw
CSRF
IDOR
Stored XSS
HTML injection |
okex.com
livecoin.net |
Max (@0xw2w) |
Bug Bounty | 2018-04-14 | 2023-06-13 |
4707 | Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud |
OS command injection
RCE |
VMware |
Brian Sullivan |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4473 | Creating unauthorized comments on Facebook Live Stream! |
Privilege escalation
Authorization flaw |
Meta / Facebook |
Binit Ghimire (@WHOISbinit) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4322 | How I hacked 40,000 user accounts of Microsoft using 2FA bypass(outlook.live.com) |
MFA bypass |
Microsoft |
Vartul Goyal (@hackvartul) |
Bug Bounty | 2019-02-05 | 2023-06-13 |
4016 | How I found the most critical bug in live bug bounty event? |
Password reset
Account takeover |
NA |
Lakshay (@inn0c3ntd3v1L) |
Bug Bounty | 2019-07-24 | 2023-06-13 |
3866 | Responsible denial of service with web cache poisoning |
DoS
Web cache poisoning |
Tesla
HackerOne
Deliveroo
Bitbucket
Paypal
Meta / Facebook
Twitter |
James Kettle (@albinowax) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3855 | Live Video facebook application (Android) its not expired when log out the device on https://www.facebook.com/settings?tab=security§ion=sessions&view |
Logic flaw |
Meta / Facebook |
Naufal Septiadi |
Bug Bounty | 2019-10-30 | 2023-06-13 |
3380 | Replying on LiveStream leading to Page Admin Disclosure: Facebook Bug Bounty |
Information disclosure |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-06-18 | 2023-06-13 |
3065 | Beyond the wall: command injection still alive. |
OS command injection |
NA |
Ahmed Constant (@a_Constant_) |
Bug Bounty | 2020-10-31 | 2023-06-13 |
3033 | Replying Comments On Someone’s LiveStream From Page is Posted as Personal Identity |
Logic flaw |
Meta / Facebook |
Prakash Panta (@Prakashpanta268) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3022 | Firefox: How a website could steal all your cookies |
Arbitrary file read |
Mozilla |
Pedro Oliveira (@kanytu) |
Bug Bounty | 2020-11-16 | 2023-06-13 |
2938 | Event Creator Is Not Able To Block The Attacker During Event Livestream |
Logic flaw |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2020-12-30 | 2023-06-13 |
2936 | Replying Comments On Someone’s Livestream From Page Is Posted As Personal Identity |
Information disclosure |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2020-12-30 | 2023-06-13 |
2635 | (POC) Remove any Facebook’s live video ($14,000 bounty) |
Logic flaw |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2021-04-17 | 2023-06-13 |
2629 | (POC) Untrim any live video on Facebook |
Authorization flaw |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2614 | Brave — Stealing your cookies remotely |
Arbitrary file read |
Brave Software |
Pedro Oliveira (@kanytu) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2541 | Writeups: Facebook Whitehat program(2021): Instagram Live setting bug |
Logic flaw |
Meta / Facebook |
Takashi Suzuki |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2433 | View Other User Private Livestream Data |
IDOR |
Meta / Facebook |
Geva (@Geva_7) |
Bug Bounty | 2021-07-03 | 2023-06-13 |