2936 | Replying Comments On Someone’s Livestream From Page Is Posted As Personal Identity |
Information disclosure |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2020-12-30 | 2023-06-13 |
2929 | Patch. Bypass. Repeat: Story of a FaceBook Page Admin Disclosure bug worth $5000 |
Information disclosure |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2021-01-04 | 2023-06-13 |
2916 | Information Disclosure through Signup Endpoint |
Information disclosure |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2910 | Unauthorized Access to OData Entities + $2K Bounty From Microsoft |
Authorization flaw
Information disclosure |
Microsoft |
Borna Nematzadeh (@LogicalHunter) |
Bug Bounty | 2021-01-10 | 2023-06-13 |
2908 | UNEP Breached, 100K+ Employee Records Accessed |
Information disclosure |
United Nations |
Jackson Henry (@JacksonHHax) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2901 | GoCD Multiple Vulnerabilities |
RCE
Information disclosure
Insecure deserialization
Security code review |
GoCD |
Denis Andzakovic |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2898 | Tale of 2 TOOTB Bugs: Google and WhatsApp |
Information disclosure
Logic flaw |
Google
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2887 | ShazLocate! Abusing CVE-2019-8791 & CVE-2019-8792 |
Insecure deeplink
Information disclosure
Android |
Google
Apple |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2021-01-17 | 2023-06-13 |
2886 | Let’s know How I have explored the buried secrets in React Native application |
Information disclosure
Hardcoded credentials |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2884 | The Embedded YouTube Player Told Me What You Were Watching (and more) |
Information disclosure |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2881 | [Bug Bounty] 600$ Info Disclosure: obtain any user’s backup data |
Information disclosure
IDOR |
NA |
Tommaso De Ponti |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2877 | Staff Information Disclosure on Support Ticketing System ($x,xxx) |
Information disclosure |
NA |
Ph.Hitachi |
Bug Bounty | 2021-01-22 | 2023-06-13 |
2876 | Page Admin Disclosure When Replying Comments |
Information disclosure |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2021-01-22 | 2023-06-13 |
2851 | Android apk leaks access token to takeover the whole infrastructure |
Information disclosure
Hardcoded credentials
Android |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2847 | Disclose the FB profile of Facebook employees who create official announcement messages (Bug Bounty) |
Information disclosure |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-02-01 | 2023-06-13 |
2844 | 1st Facebook Bug Bounty | Disclose page’s admin to mod/admin of group |
Information disclosure |
Meta / Facebook |
nhiephon (@_nhiephon) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2835 | Page Admin Disclosed In Groups Due To Improper Session Handling In Facebook Web |
Information disclosure |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2818 | Hacking Chess.com and Accessing 50 Million Customer Records |
Reflected XSS
Information disclosure
Account takeover |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2810 | How I Hacked Everyone’s Resume/CV’s and Got €€€ |
IDOR
Authorization flaw
Information disclosure |
NA |
Vishal Bharad |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2776 | Let’s know How I have explored the buried secrets in Xamarin application |
Hardcoded API keys
Information disclosure |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-02-21 | 2023-06-13 |
2762 | Somebody Call The Plumber, GraphQL is Leaking Again… |
Information disclosure
GraphQL |
NA |
N0ur5 |
Bug Bounty | 2021-02-27 | 2023-06-13 |
2757 | Somebody Call The Plumber, GraphQL is Leaking Again… |
Information disclosure
GraphQL |
NA |
N0ur5 |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2749 | Secret Key Exposure in API Config Directory |
Information disclosure |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2748 | Exploiting CORS to perform an IDOR Attack leading to PII Information Disclosure |
CORS misconfiguration
Information disclosure |
NA |
Harsh Parekh (@notmarshmllow) |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2737 | The easiest $2500 I got it from bug bounty program |
Information disclosure |
Uber |
Abdullah Mohamed (@3bodymo_) |
Bug Bounty | 2021-03-06 | 2023-06-13 |