2044 | [socket.io] Cross-Site Websockets Hijacking |
Cross-Site Websocket Hijacking (CSWH) |
Node.js third-party modules |
sh1yo (@sh1yo_) |
Bug Bounty | 2021-11-29 | 2023-06-13 |
2043 | Price Manipulation Bypass Using Integer Overflow Method |
Payment tampering
Memory corruption |
NA |
Marx Chryz |
Bug Bounty | 2021-11-29 | 2023-06-13 |
2042 | Play The Opera Please |
Browser hacking |
Opera |
Dhiraj (@RandomDhiraj) |
Bug Bounty | 2021-11-29 | 2023-06-13 |
2041 | This Microsoft Windows RCE Vulnerability Gives an Attacker Complete Control |
Memory corruption |
Microsoft |
Malcolm Stagg (@malcolmst) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2040 | NodeBB 1.18.4 - Remote Code Execution With One Shot |
RCE
XSS
Authentication bypass
Arbitrary file read |
NodeBB |
Sonar (@SonarSource) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2038 | VMware vCenter earlier versions (7.0.2.00100) has unauthorized arbitrary file read + ssrf + xss vulnerability |
LFI
SSRF
XSS
Arbitrary file read |
VMware |
Khoa Dinh (@_l0gg) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2037 | HTTP Header Injection In Citrix ADC And Citrix Gateway (CVE-2020-8300, CVE-2021-22927) |
Host header injection
XSS |
Citrix Systems |
Wolfgang Ettlinger |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2036 | Microsoft Teams – CSV Injection |
CSV injection |
Microsoft |
Christian Becker (@0xchrisb) |
Bug Bounty | 2021-12-01 | 2023-06-13 |
2035 | P1 _Bug in Apple that phase “old is Gold |
Logic flaw |
Apple |
Saurabh Sankhwar (@mr_encryption) |
Bug Bounty | 2021-12-01 | 2023-06-13 |
2033 | This shouldn%27t have happened: A vulnerability postmortem |
Memory corruption |
Mozilla |
Tavis Ormandy (@taviso) |
Bug Bounty | 2021-12-01 | 2023-06-13 |
2032 | Easy SQLi in Amazon subsidiary using Sqlmap |
SQL injection |
Amazon |
Mostafa Mamdoh |
Bug Bounty | 2021-12-01 | 2023-06-13 |
2031 | Exploring Container Security: A Storage Vulnerability Deep Dive |
Race condition
Kubernetes |
Kubernetes |
Fabricio Voznika |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2030 | AWS SageMaker Jupyter Notebook Instance Takeover |
Self-XSS
CSRF
RCE |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2029 | Bypassing Box’s Time-based One-Time Password MFA |
OTP bypass
MFA bypass |
Box |
Tal Peleg |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2028 | Disclose Ad Accounts linked with Instagram Accounts |
Information disclosure
Logic flaw
GraphQL |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2027 | Write Up – XSS Stored In files.slack.com Via XML/SVG File (iOS) – $1,000 USD |
XSS |
Slack |
Omar Espino (@omespino) |
Bug Bounty | 2021-12-03 | 2023-06-13 |
2026 | How I accessed the Sensitive document which I had already deleted |
Privacy issue |
NA |
Pawan Chhabria (@heybenchmarkkk) |
Bug Bounty | 2021-12-04 | 2023-06-13 |
2024 | How I managed to hack User accounts of a billion-dollar sport platform |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2021-12-04 | 2023-06-13 |
2023 | This is how i was able to See and Delete your Private Facebook Portal photos |
IDOR |
Meta / Facebook |
Abhishek Pathak (@pathleax) |
Bug Bounty | 2021-12-04 | 2023-06-13 |
2022 | Accidental IDOR in eLearnSecurity to Knowing Your Address and Cert You Bought. |
IDOR |
INE |
Anugrah SR (@cyph3r_asr) |
Bug Bounty | 2021-12-05 | 2023-06-13 |
2021 | SSRF vulnerability in AppSheet - Google VRP |
SSRF |
Google |
David Nechuta (@david_nechuta) |
Bug Bounty | 2021-12-05 | 2023-06-13 |
2020 | Microsoft Azure Portal – CSV Injection |
CSV injection |
Microsoft |
Christian Becker (@0xchrisb) |
Bug Bounty | 2021-12-06 | 2023-06-13 |
2019 | Hacking into Admin Panel of U.S Federal government system C.A.R.S — without credentials. |
Client-side enforcement of server-side security
Privilege escalation |
U.S. General Services Administration |
Hazem Brini (@ImJungsuu) |
Bug Bounty | 2021-12-07 | 2023-06-13 |
2018 | How I was able to change Reddit acquired Dubsmash%27s music library sound tracks%27 titles |
IDOR |
Reddit |
Sandeep Hodkasia (@sandeephodkasia) |
Bug Bounty | 2021-12-07 | 2023-06-13 |
2017 | Windows 10 RCE: The exploit is in the link |
RCE |
Microsoft |
Fabian Bräunlein |
Bug Bounty | 2021-12-07 | 2023-06-13 |