2255 | How @Mailru traeted my report on their program |
AWS misconfiguration |
Mail.ru |
Aý Oùb (@Yukusawa18) |
Bug Bounty | 2021-09-03 | 2023-06-13 |
2252 | Bypassed! and uploaded a sweet reverse shell |
Unrestricted file upload |
NA |
Ajay Sharma (@security_donut) |
Bug Bounty | 2021-09-05 | 2023-06-13 |
2251 | Business Logic Errors - Must Vote |
Logic flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-09-05 | 2023-06-13 |
2250 | Eye for an eye: Unusual single click JWT token takeover |
Open redirect
JWT
Account takeover |
JetBrains |
Yurii Sanin (@SaninYurii) |
Bug Bounty | 2021-09-05 | 2023-06-13 |
2249 | Anti-crawler Burp Suite RCE |
RCE
Browser hacking |
PortSwigger |
Wfox |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2248 | How I can take over any user’s account with their mobile number |
Account takeover
OTP bypass
Authentication bypass |
NA |
Sushmitha Katikitala |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2247 | 2 CSRF 1 IDOR on Google Marketing Platform |
IDOR
CSRF |
Google |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2246 | SSD Advisory – NETGEAR D7000 Authentication Bypass |
Authentication bypass |
Netgear |
- |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2245 | Full structure takeover to many brands of company |
Directory listing
Information disclosure |
NA |
Abdelrahman Khaled |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2244 | SSRF in PDF export with PhantomJs |
SSRF
XSS
LFI |
NA |
أنس روبي (@xhzeem) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2243 | 5 Different Vulnerabilities in Google’s Threadit |
DOM XSS
Clickjacking
Privilege escalation
Information disclosure |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2242 | Accessing Grofers Grafana Instance Using Shodan |
Weak credentials |
Grofers |
Lohith Gowda M (@lohigowda_in) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2241 | Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser |
Stored XSS
Local File Read |
Opera |
Renwa (@RenwaX23) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2240 | Facebook email disclosure and account takeover |
Information disclosure
Account takeover |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2239 | Account Takeover via XSS in e-signature feature worth 2500$ |
XSS
Account takeover |
NA |
Gökhan Güzelkokar (@gkhck_) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2238 | Spook.js: Attacking Google Chrome%27s Strict Site Isolation via Speculative Execution and Type Confusion |
Browser hacking
Side-channel attack
Site Isolation bypass |
Google |
Ayush Agarwal |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2237 | GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink |
Logic flaw
Information disclosure |
GitHub |
Justin Steven (@justinsteven) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2236 | Change home directory and bypass TCC aka CVE-2020-27937 |
Privacy issue
MacOS |
Apple |
Wojciech Reguła (@_r3ggi) |
Bug Bounty | 2021-09-09 | 2023-06-13 |
2235 | Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances |
Container takeover
Container escape
Privilege escalation
Cloud |
Microsoft |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2021-09-09 | 2023-06-13 |
2234 | Mistuned Part 1: Client-side XSS to Calculator and More |
XSS
Memory corruption
iOS |
Apple |
CodeColorist (@codecolorist) |
Bug Bounty | 2021-09-10 | 2023-06-13 |
2233 | How I Was Able to delete any facebook story where am I mentioned or tagged |
Logic flaw |
Meta / Facebook |
Sank Dahal (@sank68034756) |
Bug Bounty | 2021-09-10 | 2023-06-13 |
2232 | Bypassing GCP Org Policy with Custom Metadata |
Authorization flaw |
Google |
Kat Traxler (@NightmareJS) |
Bug Bounty | 2021-09-10 | 2023-06-13 |
2231 | How I found my first AEM related bug. |
LFR |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2021-09-11 | 2023-06-13 |
2229 | Exposing Millions of IRCTC Passengers%27 ticket details. |
IDOR |
IRCTC |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-09-12 | 2023-06-13 |
2227 | Escalating Azure Privileges with the Log Analytics Contributor Role |
Logic flaw |
Microsoft |
Karl Fosaaen (@kfosaaen) |
Bug Bounty | 2021-09-13 | 2023-06-13 |