320 | Improper Authentication in Android App |
Logic flaw
Authentication flaw
HTTP response manipulation |
NA |
oXnoOneXo |
Bug Bounty | 2023-03-10 | 2023-06-13 |
319 | Bugging Out: My Experience of Earning $300 for Reporting an Unexpected Bug |
Subdomain takeover |
NA |
Charlie : The Hacker |
Bug Bounty | 2023-03-10 | 2023-06-13 |
318 | CVE-2022-36413 Unauthorized Reset Password of Zoho ManageEngine ADSelfService Plus |
Password reset
OTP bruteforce
Account takeover
Authentication bypass |
Zoho (ManageEngine) |
Sky |
Bug Bounty | 2023-03-10 | 2023-06-13 |
317 | Account Takeover: An Epic Bug Bounty Story |
Account takeover
Self-XSS
Pre-account takeover |
NA |
Jaydev Ahire |
Bug Bounty | 2023-03-11 | 2023-06-13 |
316 | [Netflix][Smart TV] — Chaining Self-XSS with Session poisoning. |
Self-XSS
Cookie injection
Session management issue |
Netflix |
Lyubomir Tsirkov (@lyubo_tsirkov) |
Bug Bounty | 2023-03-11 | 2023-06-13 |
314 | The story of how I was able to chain SSRF with Command Injection Vulnerability |
SSRF
OS command injection
RCE |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2023-03-12 | 2023-06-13 |
313 | P1 Vulnerability by Bypassing the membership payment page |
Payment bypass |
NA |
Viktor Mares |
Bug Bounty | 2023-03-12 | 2023-06-13 |
311 | How I Leak Other’s Access Token by Exploiting Evil Deeplink Flaw |
Insecure deeplink
Android
Account takeover |
NA |
Crisdeo Nuel Siahaan |
Bug Bounty | 2023-03-13 | 2023-06-13 |
309 | Veeam Backup and Replication CVE-2023-27532 Deep Dive |
Local Privilege Escalation |
Veeam |
James Horseman (@JamesHorseman2) |
Bug Bounty | 2023-03-13 | 2023-06-13 |
307 | Hacking the Docker Registry with Burp Suite |
Docker Registry |
NA |
H1Xploit (@H1Xploit) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
306 | Your Browser is Not a Safe Space |
Local Privilege Escalation
Lateral movement |
NA |
Corey Ham |
Bug Bounty | 2023-03-14 | 2023-06-13 |
305 | Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability |
Privilege escalation
NTLM |
Microsoft (Outlook) |
Dominic Chell (@domchell) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
304 | Vulnerabilities in the TPM 2.0 reference implementation code |
Memory corruption
Out-of-bounds Read
Out-of-bounds Write |
Microsoft
VMware
Google
IBM
Lenovo
Qemu
Nuvoton
Trusted Computing Group
STMicroelectronics
Aruba Networks
CERT/CC
libtpms |
Francisco Falcon (@fdfalcon) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
303 | Producing a POC for CVE-2022-42475 (Fortinet RCE) |
Memory corruption
RCE
Integer overflow
Heap overflow |
Fortinet |
Alain Mowat (@plopz0r) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
302 | CVE-2023–24625 / IDOR in Faveo Service Desk |
IDOR |
Faveo |
cupc4k3 |
Bug Bounty | 2023-03-14 | 2023-06-13 |
299 | Backend Parameter Injection --> RCE |
RCE
HTTP parameter pollution
OS command injection |
NA |
Austin (@systemdumb) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
297 | LFI - An Interesting Tweak |
LFI |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-03-15 | 2023-06-13 |
296 | Emotional Rollercoaster: A Unique Case Study of Bypassing Antivirus and Firewall by Abusing PostgreSQL |
RCE
Old components with known vulnerabilities |
NA |
Yousef Amery (@YousefAmery) |
Bug Bounty | 2023-03-15 | 2023-06-13 |
295 | Bypassing Character Limit - XSS Using Spanned Payload |
XSS
Account takeover |
NA |
SMHTahsin33 (@SMHTahsin33) |
Bug Bounty | 2023-03-15 | 2023-06-13 |
294 | OAuth 2.0 Authentication Misconfiguration |
OAuth
Account takeover
Open redirect
Token leak |
NA |
Mohamed Lakhdar Metidji (@minometidjii) |
Bug Bounty | 2023-03-16 | 2023-06-13 |
291 | SSRF Cross Protocol Redirect Bypass |
SSRF |
NA |
Szymon Drosdzol |
Bug Bounty | 2023-03-16 | 2023-06-13 |
290 | How I chained multiple High-impact vulnerabilities to create a critical one. |
Account takeover
IDOR
OTP bypass
HTTP response manipulation |
NA |
Vinay Jagetiya (@princej_76) |
Bug Bounty | 2023-03-17 | 2023-06-13 |
288 | Directory Traversal and LFI worth $400 |
Path traversal |
NA |
Hritik Thapa |
Bug Bounty | 2023-03-17 | 2023-06-13 |
286 | Remote code execution in BIRT Viewer ≤ 4.12.0 (CVE-2023-0100) |
RCE
RFI
URL validation bypass
Security code review |
Eclipse Foundation |
Louis Wolfers (@TG91aXMK) |
Bug Bounty | 2023-03-17 | 2023-06-13 |
285 | Account Takeover with rate limit bypass |
Rate limiting bypass
Account takeover |
NA |
Shamim Ahamed (@itm4n) |
Bug Bounty | 2023-03-18 | 2023-06-13 |