4562 | Just another tale of severe bugs on a private program. |
Open redirect
SSRF
IDOR
Logic flaw |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4559 | How I was able to takeover account%27s of an Earning App |
Information disclosure |
NA |
Abbas Wafa |
Bug Bounty | 2018-10-01 | 2023-06-13 |
4556 | How i found Stored xss on your-domain.redacted.com |
XSS |
NA |
Rudra Sarkar (@rudr4_sarkar) |
Bug Bounty | 2018-10-02 | 2023-06-13 |
4554 | AWS takeover through SSRF in JavaScript |
SSRF |
NA |
Gwendal Le Coguic (@gwendallecoguic) |
Bug Bounty | 2018-10-02 | 2023-06-13 |
4552 | Exploiting an unknown vulnerability |
Logic flaw
Payment tampering |
NA |
Abhishek Bundela (@abhibundela) |
Bug Bounty | 2018-10-03 | 2023-06-13 |
4546 | Blind XML External Entities Out-Of-Band Channel Vulnerability : PayPal Case Study |
Blind XXE |
Paypal |
Abdelmoughite Eljoaydi |
Bug Bounty | 2018-10-05 | 2023-06-13 |
4544 | My First 0day Exploit (CSP Bypass + Reflected XSS) #BUGBOUNTY |
Reflected XSS
CSP bypass |
NA |
Ali Tütüncü(@alicanact60) |
Bug Bounty | 2018-10-07 | 2023-06-13 |
4540 | DOM-XSS Bug Affecting Tinder, Shopify, Yelp, and More |
DOM XSS |
Tinder |
VPN Mentor (@vpnmentor) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4537 | Payment bypass |
Payment bypass
Logic flaw |
NA |
Pratik Yadav (@PratikY9967) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4535 | Access to staging environment via User-Agent string |
Authentication bypass |
NA |
Yasser Gersy (@yassergersy) |
Bug Bounty | 2018-10-10 | 2023-06-13 |
4533 | Add description to Instagram Posts on behalf of other users - 6500$ |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-12 | 2023-06-13 |
4532 | Magic XSS with two parameters |
XSS |
NA |
Mahmood Shahabi (@m4shahab1) |
Bug Bounty | 2018-10-12 | 2023-06-13 |
4528 | Path traversal while uploading results in RCE |
Path traversal
RCE |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-10-15 | 2023-06-13 |
4523 | A Story of mishandling the Chunked Data (CVE-2018-17082) |
XSS |
PHP |
Prashanth Varma (@cymtrick) |
Bug Bounty | 2018-10-20 | 2023-06-13 |
4521 | Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature |
Logic flaw |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2018-10-22 | 2023-06-13 |
4520 | Cookie-based-injection XSS making exploitable with-out exploiting other Vulns |
XSS |
NA |
Utkarsh Agrawal (@agrawalsmart7) |
Bug Bounty | 2018-10-22 | 2023-06-13 |
4518 | XSS with HTML and how to convert the HTML into charcode() |
XSS |
Purinar Logistics |
Arif-ITSEC111 |
Bug Bounty | 2018-10-22 | 2023-06-13 |
4516 | SOAP- Based Unauthenticated Out-of-Band XML External Entity (OOB-XXE) in a Help Desk Software |
XXE |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2018-10-24 | 2023-06-13 |
4515 | DoS on Facebook Android app using 65530 characters of ZERO WIDTH NO-BREAK SPACE. |
DoS |
Meta / Facebook |
Rahul Kankrale (@RahulKankrale) |
Bug Bounty | 2018-10-25 | 2023-06-13 |
4512 | A very useful technique to bypass the CSRF protection for fun and profit. |
CSRF |
NA |
Yeasir Arafat |
Bug Bounty | 2018-10-26 | 2023-06-13 |
4511 | How Misconfigured API leaked user private information? |
IDOR
Authorization flaw |
NA |
Yeasir Arafat |
Bug Bounty | 2018-10-26 | 2023-06-13 |
4510 | Privilege Escalation like a Boss |
IDOR |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2018-10-27 | 2023-06-13 |
4509 | #BugBounty — How I was able to download the Source Code of India’s Largest Telecom Service Provider including dozens of more popular websites! |
.git folder disclosure
Source code disclosure |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-10-27 | 2023-06-13 |
4507 | Improper CSRF token handling leads to site-wide CSRF issue, chained with clickjacking = woot! Multiple sites vulnerable |
CSRF
Clickjacking |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-10-29 | 2023-06-13 |
4506 | CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services |
Memory corruption |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-10-30 | 2023-06-13 |