2226 | Hacking CloudKit - How I accidentally deleted your Apple Shortcuts |
Logic flaw |
Apple |
Frans Rosén (@fransrosen) |
Bug Bounty | 2021-09-13 | 2023-06-13 |
2225 | 10 golden minutes for taking over a Chess.com account |
Lack of rate limiting
Bruteforce
Session expiration issue |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-09-14 | 2023-06-13 |
2224 | OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers |
Local Privilege Escalation
RCE |
Microsoft |
Nir Ohfeld (@nirohfeld) |
Bug Bounty | 2021-09-14 | 2023-06-13 |
2223 | Microsoft Azure Portal – Persistent Cross-Site Scripting |
Stored XSS |
Microsoft |
Christian Becker (@0xchrisb) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2222 | How I hacked worldwide Tiktok users |
IDOR |
TikTok |
s3c (@s3c_krd) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2220 | A Facebook bug that exposes email/phone number to your friends |
Information disclosure
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2219 | This is why you shouldn’t trust your Federated Identity Provider |
OAuth
Account takeover
Authentication bypass |
NA |
Soufiane Habti (@wld_basha) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2218 | How I was able to find 100+ XSS in United nations Bug Bounty Program |
XSS |
United Nations |
mrpentestguy (@MR_iambatman) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2217 | Weaponizing Reflected XSS to Account Takeover |
XSS
Account takeover |
NA |
Hassan Shahid (@pwnsauc3) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2216 | A Small Tale of Account Takeover … |
IDOR
Account takeover |
NA |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2215 | How to have free Internet WIFI on United Airlines flights |
Payment tampering
Logic flaw |
United Airlines |
Philippe Delteil (@PhilippeDelteil) |
Bug Bounty | 2021-09-17 | 2023-06-13 |
2214 | All Your (d)Base Are Belong To Us, Part 1: Code Execution in Apache OpenOffice (CVE-2021–33035) |
RCE
Memory corruption |
Apache |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-09-17 | 2023-06-13 |
2213 | From Google Dorking to Information Disclosure |
Information disclosure
Missing authentication |
NA |
MikeChan |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2212 | From phpinfo page to many P1 bugs and RCE. [Symfony] |
File disclosure
Information disclosure
RCE |
NA |
Abdelrahman Khaled |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2211 | A small change, and things go in your hand : Story of a $250 bounty |
Information disclosure |
NA |
Fardeen Ahmed (@fardeenahmed411) |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2210 | Admin access !! |
Privilege escalation
Broken Access Control |
NA |
th3.d1p4k (@DipakPanchal05) |
Bug Bounty | 2021-09-19 | 2023-06-13 |
2209 | Chaining bugs for better bounties |
SSRF
XSS
Information disclosure |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-09-19 | 2023-06-13 |
2208 | Unlimited report user in Instagram (Facebook) leads to abuse risk. |
Lack of rate limiting |
Meta / Facebook |
Mano Prasanth |
Bug Bounty | 2021-09-20 | 2023-06-13 |
2207 | 5 RCEs in npm for $15,000 |
RCE |
NA |
Robert Chen (@NotDeGhost) |
Bug Bounty | 2021-09-20 | 2023-06-13 |
2206 | Mama Always Told Me Not to Trust Strangers without Certificates |
MiTM
RCE |
Netgear |
Adam (@AdamOfDc949) |
Bug Bounty | 2021-09-21 | 2023-06-13 |
2205 | RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through |
RCE
Path traversal |
Citrix Systems |
Markus Wulftange (@mwulftange) |
Bug Bounty | 2021-09-21 | 2023-06-13 |
2204 | Cookie Stealing via Clickjacking using Burp collaborator |
Clickjacking |
NA |
Anurag__Verma |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2203 | A fever Worth 750$- [Accessing Private Projects ] |
IDOR
Information disclosure |
Mozilla |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2202 | mXSS in support.mozilla.org |
XSS |
Mozilla |
Guilherme Keerok (@k33r0k) |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2201 | Autodiscovering the Great Leak |
Domain name collision |
Microsoft |
Amit Serper (@0xAmit) |
Bug Bounty | 2021-09-22 | 2023-06-13 |