5250 | Facebook – Send Notifications to any User Exploit |
Logic flaw |
Meta / Facebook |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2014-04-07 | 2023-06-13 |
5187 | Watch Paint Dry: How I got a game on the Steam Store without anyone from Valve ever looking at it. |
Authorization flaw
Logic flaw |
Valve |
Ruby Nealon (@_ruby) |
Bug Bounty | 2016-03-29 | 2023-06-13 |
5179 | Facebook movies recommendation vulnerability – A bug capable of erasing all your important notifications! |
Logic flaw
DoS |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2016-05-05 | 2023-06-13 |
5175 | Facebook Vulnerability – a "Cute Bug" that reveals the "likes" of deleted posts regardless of their privacy settings |
Logic flaw |
Meta / Facebook |
Mohamed Aty (@m_aty) |
Bug Bounty | 2016-05-13 | 2023-06-13 |
5163 | Uber Hacking: How we found out who you are, where you are and where you went |
Bruteforce
Information disclosure
Logic flaw
IDOR |
Uber |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2016-06-24 | 2023-06-13 |
5160 | How I Could Steal Money from Instagram, Google and Microsoft |
Logic flaw |
Google
Microsoft
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-07-15 | 2023-06-13 |
5126 | Leak Private Videos [Vimeo Bug Bounty] |
Logic flaw
Authorization flaw |
Vimeo |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-10-23 | 2023-06-13 |
5111 | I got emails - G Suite Vulnerability |
Logic flaw
Authorization flaw |
Google
Meta / Facebook
Yelp |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-02-02 | 2023-06-13 |
5108 | Facebook Groups Hack |
Authorization flaw
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-04 | 2023-06-13 |
5106 | Bypassed Facebook Phone Number Security |
Authorization flaw
Logic flaw
Information disclosure |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-10 | 2023-06-13 |
5105 | Facebook Account Recovery Form (CONFLICTING) |
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-13 | 2023-06-13 |
5104 | Vulnerabilities in Facebook Login Approval Form |
Authorization flaw
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-14 | 2023-06-13 |
5097 | How I got your phone number through Facebook |
Logic flaw |
Meta / Facebook |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
5078 | I got emails — G Suite Vulnerability |
Logic flaw |
Google
Yelp
Meta / Facebook |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-05-05 | 2023-06-13 |
5069 | Paypal Mobile Verification And Payment Restrictions Bypass |
Logic flaw |
Paypal |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5027 | Business Logic Vulnerabilities Series: A brief on Abusing Invitation Systems |
Logic flaw |
Meta / Facebook |
Ali Kabeel |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5018 | Disabling New Emails From Facebook Without Email Owner Interaction |
Logic flaw
Authorization flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-07-26 | 2023-06-13 |
5012 | Business Logic Vulnerabilities Series: How I became invisible and immune to blocking on Instagram! |
Logic flaw |
Meta / Facebook |
Ali Kabeel |
Bug Bounty | 2017-07-31 | 2023-06-13 |
5010 | How to confirm a Google user’s specific email address (Bug Bounty Submission) |
Logic flaw |
Google |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2017-08-09 | 2023-06-13 |
4984 | How I hacked hundreds of companies through their helpdesk |
Ticket Trick
Logic flaw |
GitLab
Slack
Yammer
Kayako
Zendesk |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2017-09-10 | 2023-06-13 |
4950 | How I hacked Google’s bug tracking system itself for $15,600 in bounties |
Logic flaw |
Google |
Alex Birsan (@alxbrsn) |
Bug Bounty | 2017-10-30 | 2023-06-13 |
4939 | Stealing bitcoin wallet backups from blockchain.info |
Logic flaw |
Blockchain.info |
Shashank (@cyberboyIndia) |
Bug Bounty | 2017-11-11 | 2023-06-13 |
4936 | How signing up for an account with an @company.com email can have unexpected results |
Logic flaw |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-11-15 | 2023-06-13 |
4918 | How I Was Able To See The Bounty Balance Of Any Bug Bounty Program In HackerOne |
Logic flaw |
HackerOne |
Cj Legacion (@LegacionCj) |
Bug Bounty | 2017-12-06 | 2023-06-13 |
4879 | Here’s how I could’ve ridden for free with Uber |
Logic flaw |
Uber |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-01-26 | 2023-06-13 |