2781 | Build Pipeline Security |
RCE |
AWS |
xssfox (@xssfox) |
Bug Bounty | 2021-02-18 | 2023-06-13 |
2777 | RCE On A Laravel Private Program |
RCE |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2021-02-20 | 2023-06-13 |
2753 | Big Bugs: Bitbucket Pipelines Kata Containers Build Container Escape |
RCE |
NA |
Alex Chapman (@ajxchapman) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2745 | How I Might Have Hacked Any Microsoft Account |
Account takeover
Password reset
Bruteforce
MFA bypass |
Microsoft |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-03-02 | 2023-06-13 |
2743 | Content Injection (RCE) in Yandex Browser for Android [2018] |
MiTM |
Yandex |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2712 | CVE-2021-27076: A Replay-style Deserialization Attack Against Sharepoint |
Insecure deserialization
RCE |
Microsoft |
Simon Zuckerbraun (@HexKitchen) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2706 | TikTok for Android 1-Click RCE |
RCE
XSS
Insecure intent
Android |
TikTok |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2699 | OTP brute-force via rate limit bypass |
Bruteforce
Lack of rate limiting
OTP bypass |
NA |
Bilal Muqeet (@blmqt) |
Bug Bounty | 2021-03-21 | 2023-06-13 |
2677 | Zero click vulnerability in Apple’s macOS Mail |
Account takeover
Information disclosure
RCE |
Apple |
Mikko Kenttälä (@Turmio_) |
Bug Bounty | 2021-04-01 | 2023-06-13 |
2667 | Code execution as root via AT commands on the Quectel EG25-G modem |
OS command injection
RCE |
Quectel |
nns |
Bug Bounty | 2021-04-03 | 2023-06-13 |
2666 | RCE on Starbucks Singapore and more for $5600 |
RCE
Unrestricted file upload |
Starbucks |
Kamil Onur Özkaleli (@ko2sec) |
Bug Bounty | 2021-04-04 | 2023-06-13 |
2664 | Remote code execution through unsafe unserialize in PHP |
Insecure deserialization
RCE |
NA |
Sjoerd Langkemper |
Bug Bounty | 2021-04-04 | 2023-06-13 |
2661 | Intro to Open-source Bug Bounty |
Path traversal |
Mailtrain |
Arjun Shibu (@0xsegf) |
Bug Bounty | 2021-04-05 | 2023-06-13 |
2658 | Apple TV for Fire OS code execution |
RCE
Insecure storage
Man-in-the-Disk attack |
Apple |
Razvan Sima (@0xraaz) |
Bug Bounty | 2021-04-05 | 2023-06-13 |
2656 | Chaining an Blind SSRF bug to Get an RCE |
Blind SSRF
RCE |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-07 | 2023-06-13 |
2649 | ELECTRIC CHROME - CVE-2020-6418 on Tesla Model 3 |
RCE
Browser hacking |
Tesla
Google |
Chris Williams (@HawaiiFive0day) |
Bug Bounty | 2021-04-12 | 2023-06-13 |
2648 | You Talking To Me? |
RCE
Browser hacking |
Google |
Li JianTao (@cursered) |
Bug Bounty | 2021-04-12 | 2023-06-13 |
2647 | Exploiting Struts RCE on 2.5.26 |
RCE
Double OGNL evaluation |
Apache Struts |
Chris (@mc_0wn) |
Bug Bounty | 2021-04-12 | 2023-06-13 |
2645 | Advisory: Cisco RV34X Series – Authentication Bypass and Remote Command Execution |
Authentication bypass
OS command injection
RCE |
Cisco |
T. Shiomitsu |
Bug Bounty | 2021-04-13 | 2023-06-13 |
2643 | Vulnerability Spotlight: Multiple remote code execution vulnerabilities in Microsoft Azure Sphere |
RCE |
Microsoft |
Cisco Talos |
Bug Bounty | 2021-04-14 | 2023-06-13 |
2640 | Allow arbitrary URLs, expect arbitrary code execution |
RCE |
Nextcloud
Telegram
VLC |
Fabian Bräunlein |
Bug Bounty | 2021-04-15 | 2023-06-13 |
2634 | Discoure themes OS Command Injection |
RCE
OS command injection |
Discourse |
joernchen (@joernchen) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2630 | Exploiting Unrestricted File Upload to achieve Remote Code Execution on a bug bounty program |
Unrestricted file upload
RCE |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2622 | CVE-2021-30481: Source engine remote code execution via game invites |
RCE
Integer underflow |
Valve |
floesen (@floesen_) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2621 | DMCA.COM Hack, Full Disclosure (With Proof-of-Concept) |
Privilege escalation
Client-side enforcement of server-side security
Stored XSS
Broken Access Control |
DMCA |
Joël Aviad Ossi |
Bug Bounty | 2021-04-21 | 2023-06-13 |