625 | Bypass firewalls with of-CORs and typo-squatting |
CORS misconfiguration |
Tesla |
Chris Grayson |
Bug Bounty | 2023-01-02 | 2023-06-13 |
624 | Access to page with default credentials that require authenticate $$$. |
Default credentials |
NA |
Adham sayed (doosec101) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
623 | Vue JS Reflected XSS |
Reflected XSS
Blind XSS
CORS misconfiguration
UI redressing |
NA |
sid0krypt (@Siddhar07949650) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
622 | Fetch Diversion |
DOM XSS |
NA |
Nicolas Christin (@acut3hack) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
621 | Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More |
Account takeover
SSO
RCE
Authorization bypass
SQL injection
Mass assignment
Information disclosure |
Kia
Honda
Infiniti
Nissan
Acura
Mercedes-Benz
Hyundai
Genesis
BMW
Rolls Royce
Ferrari
Spireon
Ford
Reviver
Porsche
Toyota
Jaguar
Land Rover
SiriusXM |
Sam Curry (@samwcyo) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
619 | CVE-2022-25026 & CVE-2022-25027: Vulnerabilities in Rocket TRUfusion Enterprise |
Authentication bypass
SSRF |
Rocket Software |
Tom Wedgbury |
Bug Bounty | 2023-01-04 | 2023-06-13 |
618 | Prototype Pollution in Python |
Prototype pollution
DoS |
NA |
Abdulraheem Khaled (@Abdulrah33mK) |
Bug Bounty | 2023-01-04 | 2023-06-13 |
617 | Blind XSS in Email Field; 1000$ bounty |
Blind XSS |
NA |
Yaseen Zubair |
Bug Bounty | 2023-01-05 | 2023-06-13 |
616 | PandoraFMS - Pre-Auth Remote Code Execution |
RCE
Path traversal
Arbitrary file upload
LFI
Security code review |
PandoraFMS |
esj4y (@esj4y) |
Bug Bounty | 2023-01-06 | 2023-06-13 |
614 | Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability |
CORS misconfiguration |
Google |
Borna Nematzadeh (@LogicalHunter) |
Bug Bounty | 2023-01-06 | 2023-06-13 |
613 | Advanced CSRF Exploitation |
CSRF
Stored XSS |
NA |
Sandro Einfeldt |
Bug Bounty | 2023-01-07 | 2023-06-13 |
612 | The Bug That Kept On Giving :: PaymentBypass :: QR CODE |
Payment bypass |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-01-07 | 2023-06-13 |
611 | The SSRF that Brought down a Server |
SSRF
DoS |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-01-07 | 2023-06-13 |
610 | Bug hunting: Open access to S3 bucket |
AWS misconfiguration |
NA |
Raghul Raj |
Bug Bounty | 2023-01-09 | 2023-06-13 |
609 | Uploading the Webshell using filename of Content-Disposition Header Story! |
Unrestricted file upload
Arbitrary file write |
NA |
Yashar Mohagheghi |
Bug Bounty | 2023-01-09 | 2023-06-13 |
606 | Hacking Hackers for fun and profit |
Self-XSS
Blind XSS |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
605 | Full Team Takeover |
Broken Access Control
Logic flaw |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
603 | Practical Example Of Client Side Path Manipulation |
Client-side Path Traversal |
NA |
Antoine Roly (@aroly) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
602 | Full Team Takeover |
Account takeover
Broken Access Control |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
601 | How I Earned $1000 From Business Logic Vulnerability (account takeover) |
Logic flaw
Account takeover |
NA |
andika |
Bug Bounty | 2023-01-10 | 2023-06-13 |
598 | Client-Side SSRF to Google Cloud Project Takeover [Google VRP] |
SSRF
CSRF
Open redirect |
Google |
Dohyun Lee |
Bug Bounty | 2023-01-12 | 2023-06-13 |
593 | Exploiting Application Logic to Phish Internal Mailing Lists |
Phishing |
NA |
Tanner Emek (@itscachemoney) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
592 | How Browser’s Save As Feature might lead to Code Execution (CVE-2022–45415) |
RCE
Browser hacking |
Mozilla (Firefox) |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2023-01-14 | 2023-06-13 |
591 | YAFPC — Unauthenticated Remote Code Execution |
Authentication bypass
Hardcoded credentials
RCE |
NA |
Luke Paris |
Bug Bounty | 2023-01-14 | 2023-06-13 |