1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1952 | Abusing Business Logic of an Application to create backdoor in a form APP |
Logic flaw |
NA |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-01-01 | 2023-06-13 |
1948 | Story of YouTube’s Unfixable Ads Bypass |
Logic flaw |
Google |
MrMax4o4 |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1939 | Accessing GoDaddy internal instance through an email logic bug. |
Logic flaw
Privilege escalation
Account takeover |
GoDaddy |
Mostafa Mamdoh |
Bug Bounty | 2022-01-05 | 2023-06-13 |
1919 | FB Lite All Users Active Status Changed |
Logic flaw |
Meta / Facebook |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-01-14 | 2023-06-13 |
1891 | How I could have read your confidential bug reports by simple mail? |
Information disclosure
Logic flaw |
Microsoft |
Sudhakar Muthumani (@Sudhakarmuthu04) |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1864 | IDOR vulnerability on invoice and weak password reset leads to account take over |
IDOR
Password reset
Account takeover
Payment tampering
Logic flaw |
NA |
Damaidec |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1842 | Google Security Misconfiguration Leads to Account Takeover ! |
Logic flaw
Spoofing |
Google |
Harsh Banshpal |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1815 | Bug Report; Bypassing Weekly Limits In Basic (Free) LinkedIn Account |
Logic flaw |
LinkedIn |
Ashok Acharya |
Bug Bounty | 2022-02-16 | 2023-06-13 |
1812 | My first report on HackerOne: A logic flaw in npm |
Logic flaw |
GitHub |
ElSec (@ElSec_) |
Bug Bounty | 2022-02-16 | 2023-06-13 |
1796 | Send a Email to me and get kicked out of Google Groups !! — #GoogleVRP — A Feature that almost broke Google Groups !! |
Logic flaw
Authorization flaw |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2022-02-20 | 2023-06-13 |
1792 | How I could’ve bypassed the 2FA security of Instagram once again? |
MFA bypass
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2022-02-21 | 2023-06-13 |
1787 | Stealing a few more GitHub Actions secrets |
Logic flaw |
GitHub |
Teddy Katz (@not_aardvark) |
Bug Bounty | 2022-02-23 | 2023-06-13 |
1783 | Bypassing default visibility for newly-added email in Facebook(Part I - Submitting I.D) |
Logic flaw |
Meta / Facebook |
Kent Jarold Abulag (@wkemenhehehegsg) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1782 | A Weird Price Tampering Vulnerability |
Payment tampering
Logic flaw |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1762 | Some critical vulnerabilities found with passive analysis on bug bounty programs explained |
Information disclosure
Logic flaw |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1753 | Demographic Misconfiguration on Facebook live |
Logic flaw
Authorization flaw |
Meta / Facebook |
Prajwol Dhungana (@PrajwolDhunga14) |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1718 | Bypass confirmation to add payment method. |
Email verification bypass
Logic flaw |
NA |
Yaj Desu |
Bug Bounty | 2022-03-18 | 2023-06-13 |
1671 | View Friends List of any users using “View as” | Facebook Bug bounty |
Logic flaw
Broken Access Control |
Meta / Facebook |
Ph.Hitachi |
Bug Bounty | 2022-04-02 | 2023-06-13 |
1654 | The Bug That Kept On Giving :: PaymentBypass :: Eposed Return Url |
Payment bypass
Logic flaw |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1599 | Unlock any blur text/picture without membership/subscription on Scribd.com |By Neuchi |
Payment bypass
Logic flaw |
Scribd.com |
Neil Neuchi |
Bug Bounty | 2022-04-25 | 2023-06-13 |
1597 | Package Planting: Are You [Unknowingly] Maintaining Poisoned Packages? |
Logic flaw |
GitHub |
Yakir Kadkoda |
Bug Bounty | 2022-04-26 | 2023-06-13 |
1579 | Business Logic Errors - Art of Testing Cards |
Payment bypass
Logic flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1547 | Vulnerability in Huawei%27s AppGallery can download paid apps for free |
Payment bypass
Logic flaw |
Huawei |
Dylan Roussel (@evowizz) |
Bug Bounty | 2022-05-18 | 2023-06-13 |
1533 | A business Logic issue worth $1500 |
Logic flaw |
NA |
Mohsin Khan (@tabaahi_) |
Bug Bounty | 2022-05-21 | 2023-06-13 |