2464 | Exploiting File Upload Functionality in Unique Way. |
Unrestricted file upload |
NA |
Rohit Soni (@streetofhacker) |
Bug Bounty | 2021-06-19 | 2023-06-13 |
2463 | Zero Click account Takeover |
Account takeover
Password reset |
NA |
Zahir Tariq (@ZahirTariq3) |
Bug Bounty | 2021-06-19 | 2023-06-13 |
2462 | Full Local File Read via Error Based XXE using XLIFF File |
XXE |
NA |
pwn.vg / Tomi (@mastomii) |
Bug Bounty | 2021-06-19 | 2023-06-13 |
2461 | How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It |
Account takeover
MFA bypass
Rate limiting bypass
Race condition |
Apple |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-06-19 | 2023-06-13 |
2460 | Unprivileged User with Read/Write permission to `User Access` can escalate their role to ADMIN — Privilege Escalation |
Privilege escalation |
NA |
Ertugrul Ozdemir (@ertugrulphp) |
Bug Bounty | 2021-06-20 | 2023-06-13 |
2459 | Stored XSS via Invite leading to Mass Account Takeover at Opera. |
Stored XSS |
Opera |
Samrat Gupta (@Sm4rty_) |
Bug Bounty | 2021-06-20 | 2023-06-13 |
2458 | Cracking Encrypted Credit Card Numbers Exposed By API |
Information disclosure
Weak crypto |
NA |
Craig Hays (@craighays) |
Bug Bounty | 2021-06-22 | 2023-06-13 |
2457 | Generate online votes using Race Condition Vulnerability in Woobox Web Application (Write Up) |
Race condition |
Woobox |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-06-23 | 2023-06-13 |
2456 | How i was able to get Appreciation from the organization of a website just by changing a sign..!!! |
Information disclosure
Source code disclosure |
NA |
Fardeen Ahmed (@fardeenahmed411) |
Bug Bounty | 2021-06-23 | 2023-06-13 |
2455 | Three Microsoft Store vulnerabilites |
Payment tampering
Logic flaw |
Microsoft |
Marlon Fabiano (@astrounder) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2454 | Microsoft Store free purschase vulnerabilites |
Payment tampering
Logic flaw |
Microsoft |
Marlon Fabiano (@astrounder) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2453 | MSRC is confused! 😕 |
Dependency confusion |
Microsoft |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2452 | Flywheel Subdomain Takeover |
Subdomain takeover |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2451 | A supply-chain breach: Taking over an Atlassian account |
XSS
CSRF |
Atlassian |
Dikla Barda, Yaara Shriki |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2450 | PII Leakage - Revealing Secrets |
Information disclosure |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-06-25 | 2023-06-13 |
2449 | From Information Disclosure to interesting Privilege Escalation |
Information disclosure
Account takeover
Privilege escalation |
NA |
David Shaul (@dudy2kk) |
Bug Bounty | 2021-06-25 | 2023-06-13 |
2448 | Gaining access to protected components |
Vulnerable Android content provider
Android |
NA |
DavMehtab Zafar (@0xmzfr) |
Bug Bounty | 2021-06-25 | 2023-06-13 |
2447 | Some ways to find more IDOR |
IDOR |
NA |
Thái Vũ (@thaivd98) |
Bug Bounty | 2021-06-26 | 2023-06-13 |
2444 | Escalating XSS to Arbitrary File Read |
XSS
LFI |
NA |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-06-27 | 2023-06-13 |
2443 | Misconfigured $3 Bucket - A Semi Opened Environment |
AWS misconfiguration |
Redbull |
Yukesh Kumar (@3th1c_yuk1) |
Bug Bounty | 2021-06-27 | 2023-06-13 |
2442 | Taking over Uber accounts through voicemail |
Account takeover
Voicemail hacking |
Uber |
Shubham Shah (@infosec_au) |
Bug Bounty | 2021-06-27 | 2023-06-13 |
2441 | Diving into Dependabot along with a bug in npm |
SSRF
RCE |
GitHub |
tyage (@tyage) |
Bug Bounty | 2021-06-27 | 2023-06-13 |
2440 | How I found my first Chrome bug (CVE-2021–21210) |
NAT Slipstreaming |
Google (Chrome) |
Daniel Santos (@bananabr) |
Bug Bounty | 2021-06-28 | 2023-06-13 |
2439 | gcp-dhcp-takeover-code-exec |
DHCP flood
VM takeover |
Google |
Imre Rad (@ImreRad) |
Bug Bounty | 2021-06-28 | 2023-06-13 |
2438 | How I was able to Takeover Accounts on Foxit.com |
Password reset
Account takeover |
NA |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-06-29 | 2023-06-13 |