2437 | Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) |
RCE
Insecure deserialization |
NA |
Michael Stepankin (@artsploit) |
Bug Bounty | 2021-06-29 | 2023-06-13 |
2436 | Finding DOM Polyglot XSS in PayPal the Easy Way |
DOM XSS
CSP bypass |
Paypal |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2021-06-30 | 2023-06-13 |
2435 | Testing Cookies worth $500 |
Account takeover
IDOR |
NA |
Sankalpa Acharya (@sankalpa_02) |
Bug Bounty | 2021-06-30 | 2023-06-13 |
2433 | View Other User Private Livestream Data |
IDOR |
Meta / Facebook |
Geva (@Geva_7) |
Bug Bounty | 2021-07-03 | 2023-06-13 |
2432 | Blind XSS in Apple School- Enrollment Data Disclosure |
Blind XSS |
Apple |
hackrzvijay (@hackrzvijay) |
Bug Bounty | 2021-07-05 | 2023-06-13 |
2431 | Solarwinds Serv-U 15.2.3 Share URL XSS (CVE-2021-32604) |
XSS |
SolarWinds |
Victor Kahan |
Bug Bounty | 2021-07-06 | 2023-06-13 |
2430 | Exploiting Auto-save Functionality To Steal Login Credentials |
HTML injection |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2021-07-06 | 2023-06-13 |
2429 | Kaspersky Password Manager: All your passwords are belong to us |
Weak crypto |
Kaspersky |
Jean-Baptiste Bédrune |
Bug Bounty | 2021-07-06 | 2023-06-13 |
2428 | Let’s cancel the subscription (informative) |
Logic flaw
Payment tampering |
NA |
Adnan Malik (@adnanmalikinfo) |
Bug Bounty | 2021-07-07 | 2023-06-13 |
2427 | CVE-2021-22555: Turning x00x00 into 10000$ |
Memory corruption
Local Privilege Escalation |
Google |
Andy Nguyen (@theflow0) |
Bug Bounty | 2021-07-07 | 2023-06-13 |
2426 | IDOR on clientauthconfig.googleapis.com |
IDOR |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-07-08 | 2023-06-13 |
2425 | Discovering Zero-Day Vulnerabilities in McAfee Products |
Local Privilege Escalation |
McAfee |
mr.d0x (@mrd0x) |
Bug Bounty | 2021-07-09 | 2023-06-13 |
2424 | Facebook Email/phone disclosure using Binary search |
Password reset
Information disclosure
Bruteforce |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-07-09 | 2023-06-13 |
2423 | Account Takeovers — Believe the Unbelievable |
Account takeover
Session management issue
Weak credentials
Components with known vulnerabilities
Password reset |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2021-07-09 | 2023-06-13 |
2422 | Whose app are you downloading? Link hijacking Binance’s shortlinks through AppsFlyer |
Broken link hijacking |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-07-10 | 2023-06-13 |
2421 | Reflected XSS Through Insecure Dynamic Loading |
XSS |
NA |
Greg Gibson |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2420 | Critical Bug Bounty Reports: Part 1 |
Account takeover
Password reset
RCE
Information disclosure |
NA |
Greg Gibson |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2419 | Pre-Denial Of Service (set-up 2FA on unverified account) |
Application-level DoS |
NA |
Vikash Maurya |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2418 | Trick to bypass rate limit of password reset functionality |
Rate limiting bypass |
NA |
Abdulrahman-Kamel |
Bug Bounty | 2021-07-12 | 2023-06-13 |
2417 | Broken Access control bug : Bypassing 403’s by finding another endpoint that do the same thing. |
Broken Access Control
403 bypass |
NA |
tomorrowisnew (@tomorrowisnew_) |
Bug Bounty | 2021-07-12 | 2023-06-13 |
2416 | Apple Security Bounty: A personal experience |
Permission bypass
iOS |
Apple |
Nicolas Brunner |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2415 | Part 2: Dive into Zoom Applications |
CSRF
Account takeover
Information disclosure
Session expiration issue
Authorization flaw
Logic flaw |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2414 | Unencrypted HTTP Links to Google Scholar in Search |
MiTM |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2413 | Forced Browsing to Access Admin Panel |
Forced browsing |
NA |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2412 | ($380) XSS STORED in Bigo Bug Bounty Program |
XSS |
Bigo |
Aidil Arief |
Bug Bounty | 2021-07-14 | 2023-06-13 |