5131 | Command Injection Without Spaces |
OS command injection |
NA |
Fyoorer (@ƒyoorer) |
Bug Bounty | 2016-10-02 | 2023-06-13 |
5118 | The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean |
Domain takeover |
Google
Amazon
Rackspace
DigitalOcean |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-12-05 | 2023-06-13 |
4870 | Facebook mailto injection leads to social engineering & spam attack |
Mailto injection |
Meta / Facebook |
Rahul Kankrale (@RahulKankrale) |
Bug Bounty | 2018-02-03 | 2023-06-13 |
4851 | Modifying any Ad Space and Placement |
IDOR |
Meta / Facebook |
Joshua Regio |
Bug Bounty | 2018-02-22 | 2023-06-13 |
4515 | DoS on Facebook Android app using 65530 characters of ZERO WIDTH NO-BREAK SPACE. |
DoS |
Meta / Facebook |
Rahul Kankrale (@RahulKankrale) |
Bug Bounty | 2018-10-25 | 2023-06-13 |
4288 | How I Registered Multiple Accounts in PrivateInternetAccess VPN Service for FREE |
Logic flaw |
PrivateInternetAccess VPN |
Spade |
Bug Bounty | 2019-02-20 | 2023-06-13 |
4281 | Bug Bounty 101 — Always Check The Source Code |
Lack of rate limiting
Information disclosure |
NA |
Spazzy |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4211 | SSRF Tips: SSRF/XSPA in Microsoft’s Bing Webmaster Central |
SSRF
XSPA |
Microsoft |
Elber Andre (@Elber333) |
Bug Bounty | 2019-04-09 | 2023-06-13 |
3793 | Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution. |
RCE |
Telegram |
Vladimir Metnew (@vladimir_metnew) |
Bug Bounty | 2019-12-08 | 2023-06-13 |
3657 | A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell |
XXE
RCE
Directory Traversal |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3608 | API secret key Leakage leads to disclosure of Employee’s Information |
Information disclosure |
NA |
Ace Candelario (@phspades) |
Bug Bounty | 2020-03-13 | 2023-06-13 |
3493 | $20000 Facebook DOM XSS |
DOM XSS |
Meta / Facebook |
Vinoth Kumar (@vinodsparrow) |
Bug Bounty | 2020-05-07 | 2023-06-13 |
3347 | How I made $1500 dollars using base64 decoder :) |
Information disclosure |
NA |
Dilip (@dilip_spartn) |
Bug Bounty | 2020-07-02 | 2023-06-13 |
3277 | CVE-2020–9934: Bypassing the macOS Transparency, Consent, and Control (TCC) Framework for unauthorized access to sensitive user data |
MacOS
Local Privilege Escalation
Authorization flaw |
Apple |
Matt Shockley (@mattshockl) |
Bug Bounty | 2020-07-27 | 2023-06-13 |
3217 | Open Sesame: Escalating Open Redirect to RCE with Electron Code Review |
Open redirect
RCE
Security code review |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-08-14 | 2023-06-13 |
2950 | Supply Chain Pollution: Hunting a 16 Million Download/Week npm Package Vulnerability for a CTF Challenge |
Prototype pollution |
Node.js third-party modules |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2843 | Applying Offensive Reverse Engineering to Facebook Gameroom |
Insecure deserialization |
Meta / Facebook |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2700 | Cross Site Port Attack - A Stranger’s Call |
XSPA |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-03-21 | 2023-06-13 |
2624 | Auth Bypass in Google Workspace Real Time Collaboration |
Authentication bypass
Information disclosure |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2598 | De-anonymising Anonymous Animals in Google Workspace |
Privacy issue
Information disclosure |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-04-29 | 2023-06-13 |
2406 | Logical Flaw Resulting Path Hijacking |
Namespace attack |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2021-07-16 | 2023-06-13 |
2214 | All Your (d)Base Are Belong To Us, Part 1: Code Execution in Apache OpenOffice (CVE-2021–33035) |
RCE
Memory corruption |
Apache |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-09-17 | 2023-06-13 |
2149 | Abusing Slack’s file-sharing functionality to de-anonymise fellow workspace members |
XSLeaks |
Slack |
Julien Cretel (@jub0bs) |
Bug Bounty | 2021-10-12 | 2023-06-13 |
2134 | All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646) |
RCE
Memory corruption |
Microsoft |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
1854 | Solving DOM XSS Puzzles |
DOM XSS |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2022-02-03 | 2023-06-13 |