3156 | Res-block: Extension Resources Block Attack on Chrome’s Incognito Mode |
Browser hacking |
Google |
Piyush Raj (@0x48piraj) |
Bug Bounty | 2020-09-16 | 2023-06-13 |
3149 | Remote code execution in import image task via storage bucket squatting |
RCE |
Google |
Anthony Weems |
Bug Bounty | 2020-09-19 | 2023-06-13 |
3126 | RCE on Spip and Root-Me |
RCE
SQL injection
XSS
Open redirect
Reflected file download |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3124 | Write Up – Google Bug Bounty: XSS To Cloud Shell Instance Takeover (Rce As Root) – $5,000 USD |
XSS
RCE |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2020-10-01 | 2023-06-13 |
3118 | Leveraging LFI to RCE in a website with +20000 users |
LFI
RCE |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2020-10-04 | 2023-06-13 |
3115 | 90 days, 16 bugs, and an Azure Sphere Challenge |
Local privilege escalation
RCE
DoS
Information disclosure |
Microsoft |
Cisco Talos |
Bug Bounty | 2020-10-06 | 2023-06-13 |
3114 | Our Experiences Participating in Microsoft’s Azure Sphere Bounty Program |
Local privilege escalation
RCE
Security Feature bypass |
Microsoft |
McAfee Advanced Threat Research (ATR) |
Bug Bounty | 2020-10-06 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3108 | Kud I Enter Your Server? New Vulnerabilities in Microsoft Azure |
Privilege escalation
RCE
Cloud |
Microsoft |
Intezer |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3095 | MS Enterprise app management service RCE. CVE-2022-35841 |
RCE
Local Privilege Escalation
Windows |
Microsoft |
Ceri Coburn (@_ethicalchaos_) |
Bug Bounty | 2020-10-13 | 2023-06-13 |
3093 | Discord Desktop app RCE |
RCE |
Discord |
Masato Kinugawa (@kinugawamasato) |
Bug Bounty | 2020-10-17 | 2023-06-13 |
3092 | GitHub - RCE via git option injection (almost) - $20,000 Bounty |
RCE |
GitHub |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2020-10-18 | 2023-06-13 |
3087 | GitHub Pages - Multiple RCEs via insecure Kramdown configuration - $25,000 Bounty |
RCE
Path traversal |
GitHub |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2020-10-20 | 2023-06-13 |
3082 | Samsung S20 - RCE via Samsung Galaxy Store App |
RCE |
Samsung |
F-Secure |
Bug Bounty | 2020-10-23 | 2023-06-13 |
3071 | Weblogic RCE by only one GET request — CVE-2020–14882 Analysis |
RCE
Authentication bypass
Security code review |
Oracle (WebLogic) |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2020-10-28 | 2023-06-13 |
3068 | Wormable remote code execution in Alien Swarm |
RCE |
Valve |
mev |
Bug Bounty | 2020-10-30 | 2023-06-13 |
3061 | Leaked .git folder leads to RCE |
.git folder disclosure
RCE |
NA |
James Clee (@jtcsec) |
Bug Bounty | 2020-11-01 | 2023-06-13 |
3051 | Attack of the clones: Git clients remote code execution |
RCE |
GitHub |
Vitor Fernandes (@Rapt00rVF) |
Bug Bounty | 2020-11-06 | 2023-06-13 |
3048 | Silver Peak Unity Orchestrator RCE |
RCE
Authentication bypass
Path traversal
SQL injection |
Silver Peak |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-08 | 2023-06-13 |
3030 | SD-PWN Part 2 — Citrix SD-WAN Center — Another Network Takeover |
RCE
Authentication bypass
Path traversal
OS command injection
Local Privilege Escalation |
Citrix Systems |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3025 | RCE via Server-Side Template Injection |
SSTI
RCE |
NA |
Gaurav Mishra (@gmishra010) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3021 | Hacking into (RCE) Government Server operated for the US Department of Energy’s National Nuclear Security Administration. |
RCE
OS command injection |
US Department of Energy |
Shaheen Fazim |
Bug Bounty | 2020-11-16 | 2023-06-13 |
3016 | Out of Band XXE in an E-commerce IOS app |
XXE |
NA |
Gaurang Bhatnagar (@0xgaurang) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3007 | SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover |
RCE
SSRF
Arbitrary file write
Path traversal
OS command injection
Local Privilege Escalation |
Cisco |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
3004 | SD-PWN Part 4 — VMware VeloCloud — The Last Takeover |
RCE
Authentication bypass
Default credentials
SQL injection
Path traversal
LFI |
VMware |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-26 | 2023-06-13 |