1507 | Abusing Facebook’s feature for a permanent account confusion(logic vulnerability) |
MFA bypass
DoS
Logic flaw |
Meta / Facebook |
Liv |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1492 | Exploiting Amazon active vulnerability |
Payment bypass
Logic flaw |
Amazon |
Benjamin Walter |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1484 | How to download eBooks from Google Play Store without paying for them |
Payment bypass
Logic flaw |
Google |
Yess (@Yess_2021xD) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1479 | Same bug different platform |
Logic flaw
Authorization flaw |
Meta / Facebook |
Prajwol Dhungana (@PrajwolDhunga14) |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1473 | How I was able to see likes and dislikes count which is hidden by victim | YouTube #1 |
Logic flaw
Authorization flaw |
Google |
Jay Jani (@JayJani007) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1463 | [BugTales] UnZiploc: From 0-click To Platform Compromise |
Memory corruption
Logic flaw
RCE
Local Privilege Escalation |
Huawei |
Daniel Komaromy (@kutyacica) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1458 | Proofpoint Discovers Potentially Dangerous Microsoft Office 365 Functionality that can Ransom Files Stored on SharePoint and OneDrive |
Logic flaw |
Microsoft |
Proofpoint (@proofpoint) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1452 | How I was able to see likes and dislikes count which is hidden by victim | YouTube #2 |
Logic flaw
Authorization flaw |
Google |
Jay Jani (@JayJani007) |
Bug Bounty | 2022-06-17 | 2023-06-13 |
1432 | Moderation Filter Bypass in support.mozilla.org |
Logic flaw |
Mozilla |
tomorrowisnew (@tomorrowisnew_) |
Bug Bounty | 2022-06-25 | 2023-06-13 |
1415 | The Army Of The Headless Browsers |
DDoS
Logic flaw |
Meta / Facebook |
Komodo Cyber Consulting (@Komodosec) |
Bug Bounty | 2022-06-29 | 2023-06-13 |
1408 | Facebook Portal’s business logic error lead to 500$ |
Logic flaw
Authorization flaw |
Meta / Facebook |
unurbayar amarsaikhan (@0xunuruu) |
Bug Bounty | 2022-06-30 | 2023-06-13 |
1398 | Exposing Millions of Voter ID card users’ details. |
IDOR
OTP bypass
Account takeover
Logic flaw |
CERT-In |
Aziz Al Aman (@nxtexploit) |
Bug Bounty | 2022-07-06 | 2023-06-13 |
1357 | Business logic error |
Logic flaw |
NA |
anjaneyulu kanakatla |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1296 | Business logic vulnerabilities |
Logic flaw
Payment tampering |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-07-29 | 2023-06-13 |
1273 | Irremovable guest in facebook event — Facebook bug bounty |
Logic flaw |
Meta / Facebook |
Rajiv Gyawali (@rajiv_gyawali) |
Bug Bounty | 2022-08-06 | 2023-06-13 |
1255 | Email Confirmation bypass at Instagram |
Email verification bypass
Logic flaw |
Meta / Facebook |
Avinash Kumar (@itsavinash_) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1194 | Blockchain Network is Secured! But not the apps and their Integrations |
Payment tampering
Logic flaw |
NA |
Keyur Talati |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1182 | Break the Logic: Insecure Parameters (€300) |
Parameter manipulation
Logic flaw
Mass assignment |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-08-24 | 2023-06-13 |
1138 | Viewing Instagram live streams anonymously without notifying the host |
IDOR
Logic flaw
Privacy issue |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1136 | Discovery of CVE-2022-35406 |
Logic flaw
Referer leakage |
PortSwigger |
Mr. Vrushabh (@doshi_vrushabh) |
Bug Bounty | 2022-09-03 | 2023-06-13 |
1103 | How I was able to see likes count even though is hidden by victim | YouTube |
Information disclosure
Logic flaw |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1098 | Attackers Can Bypass GitHub Required Reviewers to Submit Malicious Code |
Authorization flaw
Logic flaw |
GitHub |
Noam Dotan |
Bug Bounty | 2022-09-08 | 2023-06-13 |
986 | Vulnerabilities in Online Payment Systems |
Payment bypass
Payment tampering
Logic flaw |
NA |
Claudio Moran |
Bug Bounty | 2022-10-08 | 2023-06-13 |
928 | Bypassing Mimecast URL and File Inspection |
Secure Email Gateway bypass
Logic flaw |
Mimecast |
Patrick Sayler (@psaYler) |
Bug Bounty | 2022-10-20 | 2023-06-13 |
888 | How i was able to get free money via sending negative tokens |
Logic flaw
Payment tampering |
NA |
Mohamed Anani (@0xM5awy) |
Bug Bounty | 2022-10-28 | 2023-06-13 |