2360 | The journey from Google Honorable Mention to Hall of Fame. |
Referer leakage
Information disclosure
Password reset |
Google |
Akash basnet (@noneofyou007) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2359 | Multi Domain DOM Cross Site Scripting |
DOM XSS |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2358 | Blind XXE Leads to Internal Port Scanning Through SSRF |
XXE
SSRF |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2357 | Bug bounty - PHI/PII critical data exposure |
Information disclosure |
NA |
Molx32 |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2356 | Tale of XSS in Angular |
Reflected XSS |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2355 | Privilege Escalation | stealing user’s point | Bugcrowd |
IDOR
Privilege escalation |
NA |
Abhind Abhi |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2354 | ~/BugBounty/IDOR/”How I was able to exfiltrate any user’s credit coupons” |
IDOR |
NA |
Jai Sharma (@ja1sharma) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2353 | how to be popular |
CSRF
Type confusion |
OkCupid |
yan (@bcrypt) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2351 | Detecting Jackson deserialization vulnerabilities with CodeQL |
Insecure deserialization |
GitHub |
Artem Smotrakov (@artem_smotrakov) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2350 | How I Scored 1K Bounty Using Waybackurls |
Information disclosure |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2349 | How the use of hidden form fields lead to Email verification bypass |
Email verification bypass
Client-side enforcement of server-side security |
NA |
Yash Swarup (@wazirsec) |
Bug Bounty | 2021-08-03 | 2023-06-13 |
2348 | PostMessage Xss vulnerability on private program |
XSS
postMessage |
NA |
Youghourta Ghannei (@YoughartaG) |
Bug Bounty | 2021-08-03 | 2023-06-13 |
2347 | How I found Open Redirect on Hashnode.com |
Open redirect |
Hashnode |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-08-05 | 2023-06-13 |
2346 | Account Takeover (User + Admin) Via Password Reset |
Account takeover
Password reset
Logic flaw |
NA |
Hemant Patidar (@HemantSolo) |
Bug Bounty | 2021-08-05 | 2023-06-13 |
2345 | Do you like to read? I can take over your Kindle with an e-book |
Memory corruption
RCE
Local Privilege Escalation |
Amazon |
Slava Makkaveev |
Bug Bounty | 2021-08-06 | 2023-06-13 |
2344 | How I got Reflected Cross Site Scripting(RXSS) on Manchester Metropolitan University |
XSS |
Manchester Metropolitan University |
Santosh Bobade (@Santosh88267387) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2340 | Size Matters — CVE-2021–0485 (High) |
Local Privilege Escalation
Android |
Google |
Dimitrios Valsamaras (@Ch0pin) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2339 | CVE-2021-0090: Intel Driver & Support Assistant (DSA) Elevation Of Privilege (EOP) |
Local Privilege Escalation |
Intel |
bohops (@bohops) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2338 | CVE-2021-25738 |
RCE |
Kubernetes |
Jordy Versmissen / J0VSEC (@j0v0x0) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2337 | What is BOLA? 3-digit bounty from Topcoder ($$$) |
IDOR |
Topcoder |
can1337 (@canmustdie) |
Bug Bounty | 2021-08-09 | 2023-06-13 |
2336 | Fuzzing + IDOR = Admin TakeOver |
IDOR
Account takeover |
NA |
Gonzalo Carrasco (@0xCGonzalo) |
Bug Bounty | 2021-08-09 | 2023-06-13 |
2335 | Multiple Vulnerabilities In cPanel/WHM |
XXE
Stored XSS
Privilege escalation
CSRF
Cross-Site WebSocket Hijacking (CSWH) |
cPanel |
Adrian Tiron (@adrian__t) |
Bug Bounty | 2021-08-10 | 2023-06-13 |
2334 | OVE-20210809-0001 Visual Studio Code .ipynb Jupyter Notebook XSS (Arbitrary File Read) |
XSS
Arbitrary file read |
Microsoft |
Justin Steven (@justinsteven) |
Bug Bounty | 2021-08-11 | 2023-06-13 |
2333 | How I Bought a £240.00 Annual Subscription for Bargain £0.01 |
Payment tampering
Logic flaw |
NA |
Craig Hays (@craighays) |
Bug Bounty | 2021-08-11 | 2023-06-13 |
2332 | Weaponizing Middleboxes for TCP Reflected Amplification |
DoS |
Check Point
Cisco
F5
Fortinet
Juniper
Netscout
Palo Alto
SonicWall
Sucuri |
Kevin Bock |
Bug Bounty | 2021-08-12 | 2023-06-13 |