206 | Java Exploitation Restrictions in Modern JDK Times |
Insecure deserialization |
NA |
Florian Hauser (@frycos) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
204 | How ChatGPT helped me find a bug |
XSS
File upload |
NA |
Abhishekgk |
Bug Bounty | 2023-04-11 | 2023-06-13 |
203 | SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897) |
Memory leak |
SecurePoint |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2023-04-12 | 2023-06-13 |
202 | CVE-2023-29383: Abusing Linux chfn to Misrepresent /etc/passwd |
Local Privilege Escalation |
shadow-utils |
Tom Neaves |
Bug Bounty | 2023-04-12 | 2023-06-13 |
201 | Rooting A Common-criteria Certified Printer To Improve Opsec |
Printer hacking |
Canon |
RedTeam Pentesting (@RedTeamPT) |
Bug Bounty | 2023-04-12 | 2023-06-13 |
199 | How I got RCE in + 10 websites… |
RCE
Security misconfiguration |
NA |
m4cddr (@m4cddr) |
Bug Bounty | 2023-04-13 | 2023-06-13 |
197 | User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264) |
OAuth
OpenID Connect
Privilege escalation
Authentication flaw |
Keycloack |
Jordi Zayuelas i Muñoz |
Bug Bounty | 2023-04-14 | 2023-06-13 |
196 | From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR |
Debug mode enabled
IDOR
Information disclosure
JWT
Broken Access Control
Exposed registration page |
NA |
Aayush Vishnoi (@AayushVishnoi10) |
Bug Bounty | 2023-04-14 | 2023-06-13 |
194 | From payload to 300$ bounty: A story of CRLF injection and responsible disclosure on HackerOne |
CRLF injection |
NA |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-16 | 2023-06-13 |
192 | (CVE-2023-2017) Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension |
SSTI
RCE
Security code review |
Shopware |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
191 | A Big company Admin Panel takeover $4500 |
Authentication bypass
40x bypass
Account takeover |
NA |
nanwn |
Bug Bounty | 2023-04-17 | 2023-06-13 |
187 | Break the Logic: Playing with product ratings on a shopping site(600$) |
Logic flaw
Parameter tampering |
NA |
Fırat |
Bug Bounty | 2023-04-18 | 2023-06-13 |
184 | My First Case of SSRF Using Dirsearch |
SSRF |
NA |
Mba-oji Chiagoziem (@g0ziem) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
178 | Vulnerability Spotlight: CVE-2023-0264 |
OpenID Connect
OAuth
Authentication flaw
Privilege escalation
Security code review |
Keycloack |
Timo Müller (@mtimo44) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
177 | How I hacked hackers in Voorivex Hunt Event |
Cloudflare bypass
WAF bypass
Account takeover |
NA |
snoopy (@snoopy101101) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
176 | CVE-2022-29844: A Classic Buffer Overflow On The Western Digital My Cloud Pro Series PR4100 |
Buffer Overflow
Memory corruption
RCE |
Western Digital |
Luca Moro (@johncool__) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
175 | Uncovering a Critical Vulnerability: My Journey of Discovering CVE-2021–31589, a Reflected XSS in LinkedIn |
Components with known vulnerabilities
Reflected XSS |
LinkedIn |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
174 | Turning Vulnerability into Bounty: How CVE-2020–17453 XSS Earned Me a $500 Bounty |
Components with known vulnerabilities
XSS |
NA |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
173 | The Fuzzing Guide to the Galaxy: An Attempt with Android System Services |
Android
Fuzzing
Heap overflow
Integer overflow
Out-of-bounds Write
Memory corruption
Local Privilege Escalation |
Samsung |
Anthony Remy |
Bug Bounty | 2023-04-20 | 2023-06-13 |
170 | Turning Vulnerability into Bounty: How CVE-2020–17453 XSS Earned Me a $500 Bounty |
Components with known vulnerabilities
XSS |
NA |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
169 | CVE-2023-23525: Get Root via A Fake Installer |
Local Privilege Escalation |
Apple (macOS) |
Mickey Jin (@patch1t) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
168 | XS-Leak: Deanonymize Microsoft Skype Users by any 3rd-party websites |
XSLeaks |
Microsoft (Skype) |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2023-04-21 | 2023-06-13 |
167 | From BitLocker-Suspended to Virtual Machine |
Internal pentest |
NA |
Reino Mostert |
Bug Bounty | 2023-04-21 | 2023-06-13 |
166 | Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers |
Salesforce
Security misconfiguration
Broken Access Control |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2023-04-21 | 2023-06-13 |