Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1964Remote Code Execution in Google Cloud Dataflow RCE Google Mike Brancato (@meatballninja) Bug Bounty2021-12-282023-06-13
1963Story of a weird CSRF bug CSRF NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2021-12-292023-06-13
1961Google Cloud Shell XSS XSS Google NDevTK (@ndevtk) Bug Bounty2021-12-302023-06-13
1960How I Am Able To Crash Anyone’s Mozilla Firefox Browser By Sending An Email DoS Mozilla Sam Bug Bounty2021-12-302023-06-13
1959WhatsApp for Android Retains Deleted Contacts Locally Privacy issue Meta / Facebook Nightwatch Cybersecurity (@nightwatchcyber) Bug Bounty2021-12-302023-06-13
1958Bypassing Identity-Aware Proxy - Google Cloud Vulnerability Authorization flaw Token leak OAuth Google SebLu Bug Bounty2021-12-302023-06-13
1957Here’s How I Could Read Anyone’s Apple ID Metrics Remotely. Information disclosure Apple Faizan Ahmad Wani Bug Bounty2021-12-302023-06-13
1956My first Google HOF Broken Access Control Google RV Sharma Bug Bounty2021-12-312023-06-13
1955Bug Hunting Journey of 2021 Stored XSS Open redirect Token leak CSRF Logic flaw Information disclosure IDOR Account takeover NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2021-12-312023-06-13
1954Fixing the Unfixable: Story of a Google Cloud SSRF SSRF Google David Schütz (@xdavidhu) Bug Bounty2021-12-312023-06-13
1953One Click To Account Takeover Mass assignment NA M7.Arman (@ArmanSecurity) Bug Bounty2022-01-012023-06-13
1952Abusing Business Logic of an Application to create backdoor in a form APP Logic flaw NA Snap Sec (@snap_sec) Bug Bounty2022-01-012023-06-13
1951A tale of zero click account takeover Account takeover IDOR NA Veshraj Ghimire (@GhimireVeshraj) Bug Bounty2022-01-012023-06-13
1950doorLock: Apple HomeKit Denial of Service DoS Apple Trevor Spiniolas Bug Bounty2022-01-012023-06-13
1949The Story Of How I Bypass SSO Login Authentication bypass NA zer0d Bug Bounty2022-01-022023-06-13
1948Story of YouTube’s Unfixable Ads Bypass Logic flaw Google MrMax4o4 Bug Bounty2022-01-032023-06-13
1947How i was able to bypass a Pin code Protection Authorization flaw NA Kerolos sameh (@xko2xx) Bug Bounty2022-01-032023-06-13
1946IDOR leads to leak Private Details IDOR NA annonymous Bug Bounty2022-01-032023-06-13
1945P5 to P1: Interesting Account Takeover Account takeover Session expiration issue Password reset NA Tushar Sharma (@tusharSharma_0) Bug Bounty2022-01-032023-06-13
1944NPM might be executing malicious code in your CI without your knowledge RCE GitHub Rotem Bar (@rotembar) Bug Bounty2022-01-032023-06-13
1942SQL Injection - The File Upload Playground Unrestricted file upload SQL injection NA Jerry Shah (@Jerry) Bug Bounty2022-01-042023-06-13
1941thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality IDOR Password reset Account takeover NA Samuele Gugliotta (@indevi0us) Bug Bounty2022-01-042023-06-13
1940Breaking Parser Logic: Gain Access To NGINX Plus API — Read/Write Upstreams. Path traversal NA zoid (@z0idsec) Bug Bounty2022-01-052023-06-13
1939Accessing GoDaddy internal instance through an email logic bug. Logic flaw Privilege escalation Account takeover GoDaddy Mostafa Mamdoh Bug Bounty2022-01-052023-06-13
1938Authorization bypass — Gmail Spoofing Google 7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) Bug Bounty2022-01-062023-06-13