1344 | How i was able to bypass Open Redirect 3 times on same program. |
Open redirect |
NA |
himanshu pdy (@himanshu_pdy) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1330 | How I was able to Take over a support chat using leaked Keys |
Information disclosure |
NA |
Pliskin |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1313 | CVE-2022-26712: The POC for SIP-Bypass Is Even Tweetable |
MacOS
SIP bypass |
Apple |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1275 | How i was able to get 29 free products. | Bug Bounty |
Race condition |
NA |
Fırat |
Bug Bounty | 2022-08-06 | 2023-06-13 |
1273 | Irremovable guest in facebook event — Facebook bug bounty |
Logic flaw |
Meta / Facebook |
Rajiv Gyawali (@rajiv_gyawali) |
Bug Bounty | 2022-08-06 | 2023-06-13 |
1246 | The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors |
Privilege escalation
Cross-tenant vulnerability
OS command injection
Local Privilege Escalation
Cloud |
Google
Microsoft
Aiven |
Shir Tamari (@shirtamari) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1206 | Let%27s Dance in the Cache - Destabilizing Hash Table on Microsoft IIS! |
DoS
Web cache poisoning
Authentication bypass |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1172 | Zimbra Open Bucket Data Leak – Responsible Disclosure |
AWS misconfiguration |
Zimbra |
Raffaele Forte (@raffaele_forte) |
Bug Bounty | 2022-08-26 | 2023-06-13 |
1146 | SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250) |
Memory corruption
Local Privilege Escalation |
Ubuntu
Linux Kernel Organization |
Cedric Halbronn (@saidelike) |
Bug Bounty | 2022-09-01 | 2023-06-13 |
1141 | Google & Apache Found Vulnerable to GitHub Environment Injection |
Privilege escalation
CI/CD |
Google
Apache |
Noam Dotan |
Bug Bounty | 2022-09-01 | 2023-06-13 |
1137 | Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique) |
Web cache poisoning
XSS
DoS |
Glassdoor |
Harel (@h4r3l) |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1103 | How I was able to see likes count even though is hidden by victim | YouTube |
Information disclosure
Logic flaw |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1097 | How I was able to Bypass Philips Authentication |
Outdated component with a known vulnerability
Authentication bypass |
Philips |
ParagBagul |
Bug Bounty | 2022-09-10 | 2023-06-13 |
1090 | LiveHelperChat - Remote Code Execution via Vulnerable Theme Upload Function |
RCE |
Live Helper Chat |
Arben Shala (@arbennsh) |
Bug Bounty | 2022-09-13 | 2023-06-13 |
1022 | Practically-exploitable Cryptographic Vulnerabilities in Matrix |
Cryptographic issues |
Matrix |
Martin Albrecht (@martinralbrecht) |
Bug Bounty | 2022-09-28 | 2023-06-13 |
979 | Enter "Sandbreak" - Vulnerability In vm2 Sandbox Module Enables Remote Code Execution (CVE-2022-36067) |
RCE
Sandbox bypass |
vm2 |
Oxeye (@OxeyeSecurity) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
949 | Facebook SMS Captcha Was Vulnerable to CSRF Attack |
CSRF |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
912 | Stranger Strings: An exploitable flaw in SQLite |
Memory corruption
Buffer Overflow
DoS |
SQLite |
Andreas Kellas |
Bug Bounty | 2022-10-25 | 2023-06-13 |
888 | How i was able to get free money via sending negative tokens |
Logic flaw
Payment tampering |
NA |
Mohamed Anani (@0xM5awy) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
852 | Netgear Nighthawk R7000P AWS_JSON Unauthenticated Double Stack Overflow Vulnerability |
Memory corruption |
Netgear |
Jean-Jamil Khalife |
Bug Bounty | 2022-11-09 | 2023-06-13 |
817 | Got Another XSS using Double Encoding |
XSS |
NA |
ag3n7 |
Bug Bounty | 2022-11-17 | 2023-06-13 |
813 | Bypassing XSS filters using Double Encoding |
XSS
WAF bypass |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
809 | SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover |
Account takeover
Azure AD
Cloud |
Microsoft |
Tomer Nahum (@TomerNahum1) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
778 | Able to Mass-change profile section leads to my first $BOUNTY$ |
HTML injection
IDOR
CSRF |
NA |
SYRINE |
Bug Bounty | 2022-11-25 | 2023-06-13 |
765 | 2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation |
Authentication bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |