392 | How I got a $2000 bounty with RXSS |
Reflected XSS |
NA |
Hashir Sami Khan (@P4n7h3Rx) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
391 | Account Takeover worth of $5 |
OAuth
Account takeover |
NA |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
390 | The Tale of a Command Injection by Changing the Logo |
RCE
OS command injection
Unrestricted file upload
Directory listing
HTTP response manipulation |
NA |
0xrz (@omidxrz) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
389 | Using efficient tooling to hunt GraphQL security issues |
GraphQL |
NA |
Nishant Jain (@realArcherL) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
387 | Interesting Stored XSS in sandboxed environment to Full Account Takeover |
Stored XSS
Account takeover |
NA |
Anurag__Verma |
Bug Bounty | 2023-02-27 | 2023-06-13 |
386 | Grand Theft Auto - A peek of BLE relay attack |
Bluetooth
BLE
Car hacking |
NA |
@Kevin2600 |
Bug Bounty | 2023-02-27 | 2023-06-13 |
385 | $10.000 bounty for exposed .git to RCE |
.git folder disclosure
RCE
OS command injection |
NA |
Lev Shmelev |
Bug Bounty | 2023-02-27 | 2023-06-13 |
381 | My First Un-Expected $$$$ Digit Bounty for an Un-Expected Vulnerability |
Lack of rate limiting
Bruteforce |
NA |
Shobhit Mehta |
Bug Bounty | 2023-02-28 | 2023-06-13 |
380 | [Tips & Tricks] Exfiltrating User%27s Data Through CSV Injection |
CSV injection |
NA |
RE:HACK (@rehackxyz) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
378 | CVE-2022-38108: RCE In Solarwinds Network Performance Monitor |
Insecure deserialization
RCE
Security code review |
SolarWinds |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
377 | Empowering weak primitives: file truncation to code execution with Git |
Argument injection
RCE |
NA |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
376 | A New Vector For “Dirty” Arbitrary File Write to RCE |
Arbitrary file write
RCE |
NA |
Maxence Schmitt (@maxenceschmitt) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
375 | Broken links hijacking and CDN takeover |
Broken link hijacking
Subdomain takeover |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
374 | How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability? |
Account takeover
Authentication bypass |
NA |
Vivek Kumar Yadav (@0xd3vil) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
373 | Exfiltrating AWS Credentials via PDF Rendering of Unsanitized Input |
SSRF
HTML injection
XSS |
NA |
Cristi Vlad (@CristiVlad25) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
372 | Abusing Hop-by-Hop Header to Chain A CRLF Injection Vulnerability |
CRLF injection
Hop-by-hop header
XSS |
NA |
Simon Bräuer (@redshark1802) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
369 | Web Cache Deception Attack on a private bug bounty program |
Web cache deception |
NA |
snoopy (@snoopy101101) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
368 | How a simple IDOR impacted the data of thousands of customers of an Indian automotive giant |
Account takeover
Information disclosure
IDOR |
NA |
Kushal Jain |
Bug Bounty | 2023-03-01 | 2023-06-13 |
367 | Mining Takeovers for Fun and Profit |
Subdomain takeover |
NA |
Artur Marzano (@MacmodSec) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
366 | Traveling with OAuth - Account Takeover on Booking.com |
OAuth
Account takeover
Authentication bypass
Open redirect |
Booking.com
KAYAK |
Aviad Carmel (@AviadCarmel) |
Bug Bounty | 2023-03-02 | 2023-06-13 |
365 | Hacking the Nintendo DSi Browser |
Memory corruption
Use-After-Free
Browser hacking |
Nintendo |
Nathan Farlow (@0x1337cafe) |
Bug Bounty | 2023-03-02 | 2023-06-13 |
364 | Email Verification Bypass Worth $$$ |
Email verification bypass |
NA |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
363 | The Story of My First Reflected XSS |
Reflected XSS |
NA |
Ahmed Kamal Abu_Elwafa (@AhmedKa01184061) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
362 | How I Earned $$$ for Excessive Data Exposure Through Directory Traversal Leads to Product Price Manipulation |
Path traversal
Information disclosure
Payment bypass |
NA |
Mohamed Shibil |
Bug Bounty | 2023-03-03 | 2023-06-13 |