2148 | 500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College Ever.👨💻 |
OTP bypass
Account takeover
Password reset |
NA |
Gowtham_Naidu (@NaiduPonnana) |
Bug Bounty | 2021-10-13 | 2023-06-13 |
2138 | Exploiting Request forgery on Mobile Applications. |
CSRF
Account takeover
Android
iOS |
Pinterest |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2137 | From staging to 0 click account takeover |
Account takeover
Logic flaw |
Pinterest |
mohamad mahmoudi (@Lotus_619) |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2118 | Unauthorized access to any user’s account. |
IDOR
Authentication bypass
Account takeover |
NA |
vikram naidu (@ImVikram7msd) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2107 | How i made 500$ with XSS |
XSS
Account takeover |
NA |
Nassim Chami (@nvccim) |
Bug Bounty | 2021-11-01 | 2023-06-13 |
2091 | ChaosDB Explained: Azure%27s Cosmos DB Vulnerability Walkthrough |
Cross-tenant vulnerability
Account takeover
Privilege escalation |
Microsoft |
Nir Ohfeld (@nirohfeld) |
Bug Bounty | 2021-11-10 | 2023-06-13 |
2085 | chaining improper authentication to idor and no rate limit for mass account takeover |
Account takeover
Lack of rate limiting
CSRF
IDOR |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2080 | Exploiting CSP in Webkit to Break Authentication & Authorization |
Information disclosure
CSP leak
Account takeover |
Apple |
Sachin Thakuri (@sachinnthakuri) |
Bug Bounty | 2021-11-13 | 2023-06-13 |
2075 | Full account takeover through referral code. |
Authentication flaw
Account takeover |
Shipt |
Mostafa Mamdoh |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2063 | Exploiting OAuth: Journey to Account Takeover |
Account takeover
OAuth
XSS
Weak CSP
CSRF |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
2053 | Account Takeover in $Million Company? |
Account takeover
Password reset |
Fastmail |
0xGodson (@0xGodson_) |
Bug Bounty | 2021-11-24 | 2023-06-13 |
2012 | Account Takeover via Stored XSS |
Account takeover
Stored XSS |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
2000 | Zero Click To Account Takeover |
Account takeover
Password reset |
NA |
M7.Arman (@ArmanSecurity) |
Bug Bounty | 2021-12-14 | 2023-06-13 |
1990 | Flickr Account Takeover |
Account takeover
Authentication flaw |
Flickr |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2021-12-18 | 2023-06-13 |
1981 | How I found (P2) Broken Authentication with Zero Skill of Hacking |
Authentication bypass
Account takeover |
NA |
yoshi m lutfi (@yoshiahmadlutfi) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1973 | Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲 |
Authentication bypass
IDOR
Lack of rate limiting |
NA |
Anurag__Verma |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1966 | Bounty Evaluation GitHub = $15,000 US Dollars | Rate Limit |
Bruteforce
Email verification bypass
Account takeover |
GitHub |
Taniya Agarwal |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1965 | Full account takeover vulnerability in Minecraft |
Account takeover |
Minecraft |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1953 | One Click To Account Takeover |
Mass assignment |
NA |
M7.Arman (@ArmanSecurity) |
Bug Bounty | 2022-01-01 | 2023-06-13 |
1951 | A tale of zero click account takeover |
Account takeover
IDOR |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2022-01-01 | 2023-06-13 |
1945 | P5 to P1: Interesting Account Takeover |
Account takeover
Session expiration issue
Password reset |
NA |
Tushar Sharma (@tusharSharma_0) |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1941 | thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality |
IDOR
Password reset
Account takeover |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2022-01-04 | 2023-06-13 |
1939 | Accessing GoDaddy internal instance through an email logic bug. |
Logic flaw
Privilege escalation
Account takeover |
GoDaddy |
Mostafa Mamdoh |
Bug Bounty | 2022-01-05 | 2023-06-13 |
1932 | Host Header Injection Lead To Account Takeovers |
Host header injection
Password reset
Account takeover |
NA |
M7.Arman (@ArmanSecurity) |
Bug Bounty | 2022-01-09 | 2023-06-13 |