2998 | WonderCMS 3.1.3 - Authenticated RCE & Blind SSRF Vulnerability |
Blind SSRF
RCE |
WonderCMS |
Mas Zet (@zetc0de) |
Bug Bounty | 2020-11-29 | 2023-06-13 |
2984 | RCE via LFI Log Poisoning - The Death Potion |
RCE
LFI
Log poisoning |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2020-12-06 | 2023-06-13 |
2981 | "Important, Spoofing" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams |
RCE
Stored XSS
CSP bypass
CSTI |
Microsoft |
Oskars Vegeris |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2972 | How I dumped PII information of customers in an ecommerce site? |
AWS misconfiguration |
NA |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2962 | D-Link: Multiple Security Vulnerabilities Leading to RCE |
RCE
Authentication bypass
Information disclosure |
D-Link |
Harold Zang |
Bug Bounty | 2020-12-17 | 2023-06-13 |
2961 | Github Secrets exposed due to RCE in Formatter Action from pull_request_target event |
RCE |
Google |
Anthony Weems |
Bug Bounty | 2020-12-17 | 2023-06-13 |
2957 | Write Up: Google VRP N/A – Sandboxed Rce As Root On Apigee API Proxies |
RCE |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2020-12-19 | 2023-06-13 |
2951 | Cookie Tossing to RCE on Google Cloud JupyterLab |
Self-XSS
DoS
CSRF
RCE |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2924 | Achieving Remote Code Execution By Exploiting Variable Check Feature |
RCE |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2021-01-06 | 2023-06-13 |
2922 | Finding bugs on Chess.com |
Lack of rate limiting
Bruteforce
CSRF |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2909 | Weblogic Remote Code Execution (Exploiting CVE-2019-2725) |
RCE |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2021-01-10 | 2023-06-13 |
2902 | Making Clouds Rain :: Remote Code Execution in Microsoft Office 365 |
RCE |
Microsoft |
Steven Seeley (@steventseeley) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2901 | GoCD Multiple Vulnerabilities |
RCE
Information disclosure
Insecure deserialization
Security code review |
GoCD |
Denis Andzakovic |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2894 | Attack of the clones 2: Git CLI remote code execution strikes back |
RCE |
GitHub |
Vitor Fernandes (@Rapt00rVF) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2890 | Finding 0day to hack Apple |
RCE
ColdFusion |
Apple |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2878 | KindleDrip — From Your Kindle’s Email Address to Using Your Credit Card |
RCE |
Amazon |
Yogev Bar-On |
Bug Bounty | 2021-01-21 | 2023-06-13 |
2874 | The Secret Parameter, LFR, and Potential RCE in NodeJS Apps |
Local File Read
RCE |
NA |
CaptainFreak (@0xCaptainFreak) |
Bug Bounty | 2021-01-23 | 2023-06-13 |
2866 | BMW Bug Bounty – Account Verification Bypass writeup |
OTP bypass
Bruteforce
Lack of rate limiting |
BMW |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-01-26 | 2023-06-13 |
2857 | Remote Code Execution – LimeSurvey (CVE-2018-7556) |
RCE |
NA |
yeuchimse (@yeuchimse) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2849 | An unexpected bug |
Bruteforce |
NA |
Nitin yadav (@Nitinydv14) |
Bug Bounty | 2021-01-31 | 2023-06-13 |
2832 | Escalating SSRF to RCE |
SSRF
RCE |
NA |
Sander Wind (@SanderWind) |
Bug Bounty | 2021-02-06 | 2023-06-13 |
2800 | I Own your Cloud Shell: Taking over “Azure Cloud Shell” Kubernetes Cluster Through Unsecured Kubelet API 30,000$ Bounty |
Privilege escalation
RCE |
Microsoft |
Chen Cohen (@chencococococo) |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2799 | SHAREit Flaw Could Lead to Remote Code Execution |
Android
RCE
MiTM
Man-in-the-Disk attack
Insecure intent
Vulnerable Android content provider |
SHAREit |
Echo Duan |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2796 | Dropping a shell in Google’s Cloud SQL (the speckle-umbrella story) |
Configuration file injection
RCE |
Google |
Imre Rad (@ImreRad) |
Bug Bounty | 2021-02-16 | 2023-06-13 |