2069 | Write Up – Apple N/A: PII Information, Full Contact List, Main Phone No. And Main Icloud Email Extracted; Bug Patched: Arbitrary Local File Read Via Zip File And Symlinks On Ios Files App. |
Arbitrary file read |
Apple |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2068 | CVE-2021-42306 CredManifest: App Registration Certificates Stored in Azure Active Directory |
Information disclosure |
Microsoft |
Karl Fosaaen (@kfosaaen) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2067 | URL whitelist bypass in https://cxl-services.appspot.com |
Privilege escalation
URL validation bypass
SSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2066 | A common defect in java system-Memory DoS (include CVE-2021-2344, CVE-2021-2371, CVE-2021-2376, CVE-2021-2378) |
DoS |
Oracle |
threedr3am (@threedr3am1) |
Bug Bounty | 2021-11-18 | 2023-06-13 |
2065 | A Story of an Epic Blind Remote Code Execution(RCE) |
RCE
OS command injection |
NA |
Akash Solanki (@MAALP1225) |
Bug Bounty | 2021-11-18 | 2023-06-13 |
2064 | How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud |
Information disclosure
Authentication flaw |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
2063 | Exploiting OAuth: Journey to Account Takeover |
Account takeover
OAuth
XSS
Weak CSP
CSRF |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
2062 | Hacking Apple Security Report System |
Logic flaw
Social engineering |
Apple |
HackrzVijay (@hackrzvijay) |
Bug Bounty | 2021-11-20 | 2023-06-13 |
2061 | Open Redirect Vulnerability On Zapier: An Accidental Find |
Open redirect |
Zapier |
Monish Basaniwal |
Bug Bounty | 2021-11-21 | 2023-06-13 |
2060 | Peeping through a Web-Socket |
Cross-Site Websocket Hijacking (CSWH) |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2021-11-21 | 2023-06-13 |
2059 | [BugBounty] XSS with Markdown — Exploit & Fix on OpenSource |
XSS |
NA |
Lê Thành Phúc |
Bug Bounty | 2021-11-22 | 2023-06-13 |
2058 | GoSecure Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks |
Local Privilege Escalation |
Microsoft |
Romain Carnus |
Bug Bounty | 2021-11-22 | 2023-06-13 |
2057 | A business logic error bug worth 600$ |
Payment tampering |
NA |
Deep Patidar (@itsdeepceh) |
Bug Bounty | 2021-11-23 | 2023-06-13 |
2056 | Moodle Blind SQL injection via MNet authentication |
SQL injection |
Moodle |
rekter0 (@rekter0) |
Bug Bounty | 2021-11-23 | 2023-06-13 |
2055 | Finding XSS on .apple.com and building a proof of concept to leak your PII information |
XSS |
Apple |
Zseano (@zseano) |
Bug Bounty | 2021-11-23 | 2023-06-13 |
2054 | ModSecurity DoS Vulnerability in JSON Parsing (CVE-2021-42717) |
DoS |
ModSecurity |
theMiddle (@AndreaTheMiddle) |
Bug Bounty | 2021-11-24 | 2023-06-13 |
2053 | Account Takeover in $Million Company? |
Account takeover
Password reset |
Fastmail |
0xGodson (@0xGodson_) |
Bug Bounty | 2021-11-24 | 2023-06-13 |
2052 | Multiple Vulnerabilities In Concrete CMS – Part2 (PrivEsc/SSRF/etc) |
Privilege escalation
SSRF |
Concrete CMS |
FORTBRIDGE (@FORTBRIDGE1) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2051 | Unauthenticated Sensitive Information Disclosure at [REDACTED] |
Old components with known vulnerabilities
Information disclosure |
NA |
Rizaldi Wahaz (@wah_haz) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2050 | How I Found My First XSS Bug |
XSS |
Atlassian |
Thedarkwayg (@shadow_CLAY) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2049 | RocketChat - Monitor User Messages |
Authorization flaw |
Rocket.Chat |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2048 | WordPress Plugin Confusion: How an update can get you pwned |
Supply chain attack
WordPress plugin confusion
WordPress theme confusion |
NA |
Kamil Vavra (@vavkamil) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2047 | SSD Advisory – Chrome Ad Heavy Bypass (via history.back()) |
Browser hacking |
Google (Chrome) |
Alesandro Ortiz (@AlesandroOrtizR) |
Bug Bounty | 2021-11-26 | 2023-06-13 |
2046 | How I got my first bounty on financial sector gateway site by using Previous GraphQL vulnerabilities. |
Information disclosure
GraphQL |
NA |
Night Hawk |
Bug Bounty | 2021-11-26 | 2023-06-13 |
2045 | SEC-596 |
Reflected XSS |
cPanel |
sh1yo (@sh1yo_) |
Bug Bounty | 2021-11-29 | 2023-06-13 |