2620 | How I was able to inject XSS payload into any user%27s mailbox |
XSS |
NA |
Gaurav Popalghat (@N008x) |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2619 | Remote code execution in Homebrew by compromising the official Cask repository |
RCE |
Homebrew |
RyotaK (@ryotkak) |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2618 | New Clubhouse Security Vulnerabilities Could Happen to Any Growing Unicorn |
Logic flaw |
Clubhouse |
Katie Moussouris (@k8em0) |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2617 | PrivateDrop: Breaking and Fixing Apple AirDrop |
Privacy issue
Information disclosure |
Apple |
Alexander Heinrich |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2616 | Got Nice catch by Google |
OAuth
Open redirect
CSRF |
Google |
Parth Desani (@DesaniParth) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2615 | Telegram bug bounties: XSS, privacy issues, official bot exploitation and more… |
XSS
Authorization flaw
DoS |
NA |
Davide |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2614 | Brave — Stealing your cookies remotely |
Arbitrary file read |
Brave Software |
Pedro Oliveira (@kanytu) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2613 | Page Owners Can’t remove or change page roles of deactivated users (or if Attacker blocks the page owner) in Facebook Lite, Facebook for Android and touch.facebook.com |
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2612 | AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug |
SSRF
Open redirect |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-24 | 2023-06-13 |
2611 | RCE via Internal Access to Adminer Database Management (Critical) |
RCE |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-04-24 | 2023-06-13 |
2610 | From Wayback Machine To Account Takeover |
Account takeover
Password reset
Open redirect |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2608 | Supply Chain Attacks via GitHub.com Releases |
Logic flaw |
GitHub |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2607 | From Wayback Machine To Account Takeover |
Open redirect
Account takeover |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2606 | Reflected XSS on Microsoft |
Reflected XSS |
Microsoft |
N45HT |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2605 | CVE-2021-22204 - Recreating a critical bug in ExifTool, no Perl smarts required. |
RCE |
Exiftool |
- |
Bug Bounty | 2021-04-26 | 2023-06-13 |
2604 | Relaying Potatoes: Another Unexpected Privilege Escalation Vulnerability in Windows RPC Protocol |
Local Privilege Escalation |
Microsoft |
Antonio Cocomazzi (@splinter_code) |
Bug Bounty | 2021-04-26 | 2023-06-13 |
2603 | WordPress 5.7 XXE Vulnerability |
XXE |
WordPress |
Sonar (@SonarSource) |
Bug Bounty | 2021-04-27 | 2023-06-13 |
2602 | Exploiting XSS via Markdown on Xiaomi |
XSS |
Xiaomi |
N45HT |
Bug Bounty | 2021-04-27 | 2023-06-13 |
2601 | Reflected DOM-based XSS on DomaiNesia |
XSS |
DomaiNesia |
N45HT |
Bug Bounty | 2021-04-27 | 2023-06-13 |
2600 | How did I earn €€€€ by breaking the back-end logic of the server |
Logic flaw
Information disclosure |
NA |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2021-04-28 | 2023-06-13 |
2599 | The False Oracle — Azure Functions Padding Oracle Issue |
Padding oracle attack
Privilege escalation |
Microsoft |
polarply (@polarply) |
Bug Bounty | 2021-04-28 | 2023-06-13 |
2598 | De-anonymising Anonymous Animals in Google Workspace |
Privacy issue
Information disclosure |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-04-29 | 2023-06-13 |
2597 | A tale of Html to Pdf converter ssrf and various bypasses |
SSRF |
NA |
Jatin Aesthetic (@techyfreakk) |
Bug Bounty | 2021-04-29 | 2023-06-13 |
2596 | PHP Supply Chain Attack on Composer |
Argument injection
RCE
Supply chain attack
Security code review |
Packagist |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2021-04-29 | 2023-06-13 |
2595 | Exploiting memory corruption vulnerabilities on Android |
Memory corruption
Android |
Paypal |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-04-30 | 2023-06-13 |