469 | Disabling js for the win |
Unrestricted file upload
RCE |
NA |
Vuk Ivanovic |
Bug Bounty | 2023-02-10 | 2023-06-13 |
467 | We Hacked GitHub for a Month: Here’s What We Found |
Pre-account takeover
Broken Access Control
Email verification bypass
Logic flaw |
GitHub |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
466 | A tale of a full Business Takeover — Red Team Diaries |
MITM
Credential stuffing
Password spraying |
NA |
Dhanesh Dodia - HeyDanny (@Dhanesh_Dodia) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
464 | IDOR Leads to MASS Account Takeover |
IDOR
Account takeover |
NA |
Yaseen Zubair |
Bug Bounty | 2023-02-12 | 2023-06-13 |
463 | XXE with Auto-Update in install4j |
XXE
Security code review |
Prosys OPC |
Florian Hauser (@frycos) |
Bug Bounty | 2023-02-12 | 2023-06-13 |
462 | SSRF That Allowed Us to Access Whole Infra Web Services and Many More |
SSRF |
NA |
Basavaraj Banakar (@basu_banakar) |
Bug Bounty | 2023-02-12 | 2023-06-13 |
461 | Zip bomb attack |
Zip bomb
DoS
Unrestricted file upload |
NA |
Ramkumar Nadar |
Bug Bounty | 2023-02-12 | 2023-06-13 |
460 | CVE-2022-22655 - TCC - Location Services Bypass |
MacoS
TCC bypass |
Apple (macOS) |
Csaba Fitzl (@theevilbit) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
459 | Exploiting A Remote Heap Overflow With A Custom TCP Stack |
Memory corruption
RCE |
Western Digital |
Etienne Helluy-Lafont |
Bug Bounty | 2023-02-13 | 2023-06-13 |
458 | Hacking our way into internal DBs with hardcoded authentication keys |
JWT
SSO
Authentication bypass
Security misconfiguration |
NA |
Ophion Security (@OphionSecurity) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
457 | Bypassing SameSite=lax cookie restrictions to preform CSRF resulting to a horizontal privilege escalation via poor email verification mechanism |
CSRF |
NA |
Imad Husanovic (@deadoverflow_) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
456 | Blind Time-based SQL injection vulnerability in an Indian government website |
SQL injection |
NCIIPC |
Kartikhunt3r |
Bug Bounty | 2023-02-13 | 2023-06-13 |
455 | Bypassing CORS configurations to produce an Account Takeover for Fun and Profit |
CORS misconfiguration
Account takeover |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
454 | SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs |
SQL injection
WAF bypass |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
451 | Securing Open-Source Solutions: A Study of osTicket Vulnerabilities |
Stored XSS
Reflected XSS
SQL injection
Session fixation |
osTicket |
Miguel Correia |
Bug Bounty | 2023-02-14 | 2023-06-13 |
449 | Assumed Breach Assessment Case Study: Uncovering WeSecureApp’s Approach |
Internal pentest
Missing authentication
Hardcoded credentials
Cloud |
NA |
WeSecureApp (@wesecureapp) |
Bug Bounty | 2023-02-14 | 2023-06-13 |
447 | XSS on The MOST Popular Movie Ticket website. |
XSS |
NA |
Tarang Parmar |
Bug Bounty | 2023-02-15 | 2023-06-13 |
446 | Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability (CVE-2022-44666) (0day). |
RCE |
Microsoft (Windows) |
j00sean (@j00sean) |
Bug Bounty | 2023-02-15 | 2023-06-13 |
443 | Detecting Server-Side Prototype Pollution |
Server-side prototype pollution |
NA |
Daniel Thatcher (@_danielthatcher) |
Bug Bounty | 2023-02-15 | 2023-06-13 |
442 | Server side prototype pollution, how to detect and exploit |
Server-side prototype pollution
RCE |
NA |
BitK (@BitK_) |
Bug Bounty | 2023-02-15 | 2023-06-13 |
441 | Server-side prototype pollution: Black-box detection without the DoS |
Server-side prototype pollution
RCE |
NA |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2023-02-15 | 2023-06-13 |
440 | EoP via Arbitrary File Write/Overwite in Group Policy Client “gpsvc” – CVE-2022-37955 |
Local Privilege Escalation |
Microsoft (Windows) |
ap (@decoder_it) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
438 | The Inside Story of Finding a Reverse Transaction Vulnerability in a Financial Application |
Logic flaw
Payment tampering |
NA |
Raja Uzair Abdullah (@UzaiRaja) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
436 | Readline crime: exploiting a SUID logic bug |
Local Privilege Escalation |
Arch Linux
util-linux |
roddux |
Bug Bounty | 2023-02-16 | 2023-06-13 |
434 | Found an URL in the android application source code which lead to an IDOR |
Android
Information disclosure
IDOR |
NA |
Vengeance |
Bug Bounty | 2023-02-18 | 2023-06-13 |