2148 | 500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College Ever.👨💻 |
OTP bypass
Account takeover
Password reset |
NA |
Gowtham_Naidu (@NaiduPonnana) |
Bug Bounty | 2021-10-13 | 2023-06-13 |
2147 | Write Up – Google VRP N/A: Arbitrary Local File Read (Macos) Via <a> Tag And Null Byte (%00) In Google Earth Pro Desktop App |
Local File Read |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-10-14 | 2023-06-13 |
2146 | Remote code execution in Managed Anthos Service Mesh control plane |
RCE |
Google |
Anthony Weems |
Bug Bounty | 2021-10-15 | 2023-06-13 |
2145 | Exploitation of file’s download parameters to create potential risk of malware delivery: $200 bug! |
CSRF
RCE |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2144 | Business Logic Errors - A Logic Destruction |
Logic flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2143 | How I Escalated a Time-Based SQL Injection to RCE |
SQL injection
RCE |
Sony |
JM Sanchez / 0xEchidonut (@jmrcsnchz) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2142 | Independently Secure, Together Not So Much – A Story Of 2 WP Plugins |
RCE
Race condition
Unrestricted file upload
Security code review |
NA |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2141 | The Speckle Umbrella story — part 2 |
Information disclosure
Logic flaw |
Google |
Imre Rad (@ImreRad) |
Bug Bounty | 2021-10-18 | 2023-06-13 |
2140 | Shells And SOAP: Websphere Deserialization To RCE |
RCE
Insecure deserialization |
IBM |
Wyatt Dahlenburg (@wdahlenb) |
Bug Bounty | 2021-10-18 | 2023-06-13 |
2139 | A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection |
SQL injection
WAF bypass |
AWS |
Marc Olivier Bergeron |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2138 | Exploiting Request forgery on Mobile Applications. |
CSRF
Account takeover
Android
iOS |
Pinterest |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2137 | From staging to 0 click account takeover |
Account takeover
Logic flaw |
Pinterest |
mohamad mahmoudi (@Lotus_619) |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2136 | CVE-2021-2471 MySQL JDBC XXE |
XXE |
Oracle (MySQL) |
pyn3rd (@pyn3rd) |
Bug Bounty | 2021-10-21 | 2023-06-13 |
2135 | Unauthorized access to any Facebook user’s draft profile picture frames |
IDOR |
Meta / Facebook |
Sandeep Hodkasia (@sandeephodkasia) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2134 | All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646) |
RCE
Memory corruption |
Microsoft |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2133 | Moodle - Stored XSS and blind SSRF possible via feedback answer text |
Stored XSS
SSRF |
Moodle |
rekter0 (@rekter0) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2132 | A story of another awesome old school hacking that lead to a cool P1 bug |
403 bypass |
NA |
Vuk Ivanovic |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2131 | How i Got 3 SQL injection in just 10 minutes. |
SQL injection |
NA |
Ahmed Fatouh (@XDev05) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2129 | Discourse SNS webhook RCE |
RCE
Signature validation bypass |
Discourse |
joernchen (@joernchen) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2128 | Google Chrome Vulnerability Worth for $6K: Use After Free (CVE-2021-30573) |
Memory corruption |
Google |
Security For Everyone / S4E Team (@secforeveryone) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2127 | How I was able to revoke your Instagram 2FA |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Dhiyaneshwaran (@DhiyaneshDK) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2125 | A 7500$ Google sites IDOR |
IDOR |
Google |
Jalal (@r0ckin_) |
Bug Bounty | 2021-10-24 | 2023-06-13 |
2124 | Zimbra “nginx” Local Root Exploit |
Local Privilege Escalation |
Zimbra |
Darren Martyn (@_darrenmartyn) |
Bug Bounty | 2021-10-25 | 2023-06-13 |
2123 | An Effective 5 min recon leads to a Hall of Fame |
Information disclosure |
NA |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-10-26 | 2023-06-13 |
2122 | Zimbra “zmslapd” Local Root Exploit. |
Local Privilege Escalation |
Zimbra |
Darren Martyn (@_darrenmartyn) |
Bug Bounty | 2021-10-27 | 2023-06-13 |