646 | The OWASSRF + TabShell exploit chain |
SSRF
Path traversal
Sandbox escape |
Microsoft |
Rskvp93 (@rskvp93) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
619 | CVE-2022-25026 & CVE-2022-25027: Vulnerabilities in Rocket TRUfusion Enterprise |
Authentication bypass
SSRF |
Rocket Software |
Tom Wedgbury |
Bug Bounty | 2023-01-04 | 2023-06-13 |
611 | The SSRF that Brought down a Server |
SSRF
DoS |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-01-07 | 2023-06-13 |
607 | Lexmark MC3224adwe RCE exploit |
RCE
SSRF
Printer hacking
Unrestricted file upload
Local Privilege Escalation |
Lexmark |
blasty (@bl4sty) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
598 | Client-Side SSRF to Google Cloud Project Takeover [Google VRP] |
SSRF
CSRF
Open redirect |
Google |
Dohyun Lee |
Bug Bounty | 2023-01-12 | 2023-06-13 |
580 | How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services |
SSRF
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-01-17 | 2023-06-13 |
562 | Bypassing E2E encryption leads to multiple high vulnerabilities. |
IDOR
SSRF |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
528 | Blind XSS To SSRF |
Blind XSS
SSRF |
NA |
Akash c |
Bug Bounty | 2023-01-29 | 2023-06-13 |
504 | Host Header Injection to Complete Organization takeover |
SSRF
Host header injection
Privilege escalation |
NA |
Muhammad Umer Adeem |
Bug Bounty | 2023-02-02 | 2023-06-13 |
462 | SSRF That Allowed Us to Access Whole Infra Web Services and Many More |
SSRF |
NA |
Basavaraj Banakar (@basu_banakar) |
Bug Bounty | 2023-02-12 | 2023-06-13 |
399 | Exploits Explained: Using APIs to Execute a Server-Side Request Forgery |
SSRF |
NA |
@cor3min3r |
Bug Bounty | 2023-02-24 | 2023-06-13 |
398 | draw.io CVEs |
SSRF
OAuth
Open redirect
Token leak
Security code review |
draw.io |
@caioluders |
Bug Bounty | 2023-02-24 | 2023-06-13 |
373 | Exfiltrating AWS Credentials via PDF Rendering of Unsanitized Input |
SSRF
HTML injection
XSS |
NA |
Cristi Vlad (@CristiVlad25) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
357 | GitHub Security Lab audited DataHub: Here’s what they found |
SSRF
Insecure deserialization
Cypher injection
Authentication bypass
Authorization bypass
XSS
Open redirect
JWT
JSON injection
Cryptographic issues
Session expiration issue
Security code review |
DataHub |
Alvaro Muñoz (@pwntester) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
339 | Attacking .NET Web Services |
Security code review
Arbitrary file read
Arbitrary file write
SSRF |
Siemens |
b0yd (@rwincey) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
314 | The story of how I was able to chain SSRF with Command Injection Vulnerability |
SSRF
OS command injection
RCE |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2023-03-12 | 2023-06-13 |
301 | Finding Hundreds of SSRF Vulnerabilities on AWS |
SSRF |
AWS |
Carlos Polop |
Bug Bounty | 2023-03-14 | 2023-06-13 |
291 | SSRF Cross Protocol Redirect Bypass |
SSRF |
NA |
Szymon Drosdzol |
Bug Bounty | 2023-03-16 | 2023-06-13 |
277 | How I got access to Essilor International company customer PII INFO by AWS metadata access through SSRF |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2023-03-21 | 2023-06-13 |
250 | Found SSRF and LFI in Just 10 minutes of using burp! |
SSRF
LFI |
NA |
Khaled Mohamed (@0xElkomy) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
232 | Holiday Hunting With Aquatone |
SSRF
Missing authentication
Information disclosure |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
184 | My First Case of SSRF Using Dirsearch |
SSRF |
NA |
Mba-oji Chiagoziem (@g0ziem) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
123 | When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities |
SSRF
Unrestricted file upload
Path traversal
Cloud |
Microsoft (Azure) |
Liv Matan (@terminatorLM) |
Bug Bounty | 2023-05-04 | 2023-06-13 |
91 | Triple Threat: Breaking Teltonika Routers Three Ways |
IoT
RCE
OS command injection
SSRF
XSS |
Teltonika |
Roni Gavrilov |
Bug Bounty | 2023-05-15 | 2023-06-13 |