82 | LOLBINed — Finding “LOLBINs” In AV Uninstallers |
Local Privilege Escalation |
Kaspersky
F-Secure
Trend Micro
McAfee |
Nasreddine Bencherchali (@nas_bench) |
Bug Bounty | 2023-05-17 | 2023-06-13 |
81 | DLL Hijacking Strikes Back: Exploiting Windows on ARM RDP Client (CVE-2023-24905) |
DLL Hijacking
Local Privilege Escalation |
Microsoft (Windows) |
Dor Dali |
Bug Bounty | 2023-05-17 | 2023-06-13 |
79 | KeePass Master Password Exploit - CVE-2023-32784 - Proof Of Concept (POC) |
Plaintext Storage of a Password
Thick client |
KeePass |
Luke Kavanagh |
Bug Bounty | 2023-05-17 | 2023-06-13 |
78 | A $1,000,000 bounty? The KuCoin User Information Leak |
Information disclosure
Zendesk
Authorization flaw
Security misconfiguration |
NA |
Corben Leo (@hacker_) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
77 | How Misconfigured and Vulnerable Devices Could Expose Your Company to Physical and Cyber Threats |
IoT
Default credentials
Internal pentest |
NA |
Arben Shala (@arbennsh) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
76 | Stored Iframe Injection & Permanent Open Redirection - Zero Day |
HTML injection
Open redirect |
Discourse |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
75 | Blind OS Command Injection via Activation Request |
OS command injection |
NA |
Arumusutakimu (@arumusutakimu) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
74 | Blind OS Command Injection via Activation Request |
Memory corruption
Buffer Overflow
Out-of-bounds Read |
VMware |
Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
73 | Official extension spoofing attacks: when trusted add-ons are not so trusted |
Extension spoofing
Account takeover
XSS |
NA |
Yesenia Trejo (@Yess_2021xD) |
Bug Bounty | 2023-05-19 | 2023-06-13 |
72 | DNS Recursion Leads to DoS Attack Vivo Play (IPTV) — CVE-2023–31893 |
DoS |
Vivo |
Shooter |
Bug Bounty | 2023-05-20 | 2023-06-13 |
70 | Why You Should Always Check The Audit Log [Medium] — $500 |
Information disclosure |
NA |
Emanuel Beni Harijanto |
Bug Bounty | 2023-05-20 | 2023-06-13 |
69 | Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large Online Media Leader |
SQL injection |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-05-20 | 2023-06-13 |
67 | 2FA Bypass Using Custom Cookie Parameter |
MFA bypass
Android |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
66 | I helped a top Indian health benefits management platform from major PII leak by hacking their SQL Servers, AWS instance, DCs etc. |
SQL injection |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
64 | Red team: Journey from RCE to have total control of cloud infrastructure |
RCE
SSTI
Container escape
Kubernetes
Components with known vulnerabilities
CI/CD |
NA |
Quang Vo (@mr_r3bot) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
63 | CVE 2023 25690 - Proof of Concept |
HTTP Request Smuggling
HTTP request splitting
CRLF injection |
Apache HTTP Server |
dhmosfunk (@DSkfunk) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
61 | From Response To Request, Adding Your Own Variables Inside Of GraphQL Queries For Account Take Over |
GraphQL
IDOR
Mass assignment |
NA |
Tom Neaves |
Bug Bounty | 2023-05-23 | 2023-06-13 |
58 | Unintended Path to Exam Domination - AWS EC2 Meta-Data |
Cloud
Privilege escalation |
NA |
Dr. Michael Gschwender (@rootcathacking) |
Bug Bounty | 2023-05-24 | 2023-06-13 |
57 | how I found a tricky XSS |
XSS |
NA |
Ziad Ali |
Bug Bounty | 2023-05-24 | 2023-06-13 |
56 | Hacking my “smart” toothbrush |
IoT
Reverse engineering
NFC |
NA |
Cyrill Künzi |
Bug Bounty | 2023-05-24 | 2023-06-13 |
55 | XSS Via Qr Code |
XSS |
NA |
Ahmed Osama (A0G) |
Bug Bounty | 2023-05-25 | 2023-06-13 |
53 | Exploiting The Sonos One Speaker Three Different Ways: A Pwn2Own Toronto Highlight |
Memory corruption
RCE
Out-of-bounds Read |
Sonos |
The ZDI Research Team (@thezdi) |
Bug Bounty | 2023-05-25 | 2023-06-13 |
52 | Exploring Three Remote Code Execution Vulnerabilities in RPC Runtime |
RCE
MS-RPC
Integer overflow
Memory corruption |
Microsoft (Windows) |
Ben Barnea (@nachoskrnl) |
Bug Bounty | 2023-05-26 | 2023-06-13 |
51 | Utilizing Historical URLs of an Organization to successfully execute SQL queries — Blind SQLi |
Blind SQL injection |
NA |
Aayush Vishnoi (@AayushVishnoi10) |
Bug Bounty | 2023-05-26 | 2023-06-13 |
49 | Anonymised Penetration Test Report |
Internal pentest
RCE
ADCS
Active Directory
Kerberos
DHCPv6
LLMNR |
NA |
Volkis (@VolkisAU) |
Bug Bounty | 2023-05-28 | 2023-06-13 |