670 | A Technical Analysis of CVE-2022-22583 and CVE-2022-32800 |
MacOS
Local Privilege Escalation
SIP bypass |
Apple (macOS) |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
669 | My First Bug In Bugcrowd Platform |
Race condition |
NA |
EX_097 |
Bug Bounty | 2022-12-21 | 2023-06-13 |
668 | Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951) |
SSRF
Security code review |
Cisco |
smaury (@smaury92) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
667 | RCE on admin panel of web3 website |
RCE
Components with known vulnerabilities |
NA |
T VAMSHI |
Bug Bounty | 2022-12-21 | 2023-06-13 |
666 | Zero Click To Account Takeover (IDOR + XSS) |
IDOR
XSS
Account takeover |
NA |
Arman (@M7arm4n) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
662 | How Race Condition helped me break Business Logic of the application |
Race condition |
NA |
Inderjeet Singh (@3nc0d3dGuY) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
659 | ACSESSED: Cross-tenant network bypass in Azure Cognitive Search |
Cloud
Cross-tenant vulnerability
Privilege escalation |
Microsoft (Azure) |
Emilien Socchi (@emiliensocchi) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
658 | ENLBufferPwn (CVE-2022-47949) |
Buffer Overflow
Memory corruption
RCE |
Nintendo |
PabloMK7 (@Pablomf6) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
657 | $350 XSS in 15 minutes |
DOM XSS
JSONP |
NA |
Anton (@therceman) |
Bug Bounty | 2022-12-23 | 2023-06-13 |
655 | CRLF Injection — xxx$ — How was it possible for me to earn a bounty with the Cloudflare WAF? |
CRLF injection |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2022-12-24 | 2023-06-13 |
652 | Unusual 403 Bypass to a full website takeover [External Pentest] |
403 bypass |
NA |
Viktor Mares |
Bug Bounty | 2022-12-25 | 2023-06-13 |
651 | How I Pwned 10 Admin Panels and got rewarded 8000$+? |
Information disclosure
Credential stuffing |
NA |
Inderjeet Singh (@3nc0d3dGuY) |
Bug Bounty | 2022-12-25 | 2023-06-13 |
650 | Authentication Bypass in Nexus manager (version 3.37.3–02) |
Components with known vulnerabilities
Authentication bypass
HTTP response manipulation |
NA |
SHARAN.K |
Bug Bounty | 2022-12-26 | 2023-06-13 |
644 | Hacking a .NET API in the real world |
LFI |
NA |
Dana Epp (@DanaEpp) |
Bug Bounty | 2022-12-27 | 2023-06-13 |
641 | Unauthorized Sign-up on Subdomain of Subdomain leading to Organization takeover worth $2000 |
Exposed registration page |
NA |
Manav Bankatwala (@ManavBankatwala) |
Bug Bounty | 2022-12-28 | 2023-06-13 |
640 | Feedback Analyzer Exploitation |
Information disclosure |
NA |
hacker_might |
Bug Bounty | 2022-12-28 | 2023-06-13 |
639 | Getting Secret Key to Building Custom Burp Extension |
SQL injection |
NA |
Ashlyn Lau |
Bug Bounty | 2022-12-29 | 2023-06-13 |
638 | Account Takeover Due to Cognito Misconfiguration Earns Me €xxxx |
Amazon cognito misconfiguration
Account takeover |
NA |
Mukund Bhuva (@MukundBhuva) |
Bug Bounty | 2022-12-29 | 2023-06-13 |
636 | Exploring the World of ESI Injection |
ESI injection
WAF bypass
XSS |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2022-12-29 | 2023-06-13 |
635 | CVE-2022-38627: A journey through SQLite Injection to compromise the whole enterprise building |
SQL injection |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-12-30 | 2023-06-13 |
634 | Subdomain Hijacking Of Any Qwilr’s Customer |
Subdomain takeover |
NA |
Prial Islam Khan (@prial261) |
Bug Bounty | 2023-01-01 | 2023-06-13 |
633 | How I took over an admin panel and got $500 |
Blind XSS
Account takeover |
NA |
Muhammed Mubarak |
Bug Bounty | 2023-01-01 | 2023-06-13 |
629 | An amazing way to turn a xss into an ATO |
XSS
Account takeover |
NA |
Naka |
Bug Bounty | 2023-01-02 | 2023-06-13 |
628 | Web-Cache Poisoning $$$? Worth it? |
Web cache poisoning
XSS |
NA |
Yaseen Zubair |
Bug Bounty | 2023-01-02 | 2023-06-13 |