872 | How I could have been the administrator for all Dutch companies and create invoices. And still can be… |
Logic flaw |
Dutch Government |
bob van der staak |
Bug Bounty | 2022-11-03 | 2023-06-13 |
860 | Exploit Feature To Get High Bug impact |
Logic flaw |
NA |
Mohamed Anani (@0xm5awy) |
Bug Bounty | 2022-11-05 | 2023-06-13 |
857 | How we hacked’ Telenet’s cybersecurity quiz |
Logic flaw |
Telenet |
Mickey De Baets |
Bug Bounty | 2022-11-07 | 2023-06-13 |
851 | My First Account Takeover |
Account takeover
Logic flaw |
NA |
JAI NIRESH J |
Bug Bounty | 2022-11-09 | 2023-06-13 |
827 | Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk |
SQL injection
Logic flaw |
Zendesk |
Tal Peleg |
Bug Bounty | 2022-11-15 | 2023-06-13 |
815 | MEGA’s Unlimited Cloud Storage Vulnerability |
Logic flaw
Privilege escalation |
MEGA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2022-11-17 | 2023-06-13 |
812 | How i found 8 vulnerabilities in 24h? |
Logic flaw |
NA |
Mohamed Anani (@0xM5awy) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
807 | From Static domain to Account Takeover |
Account takeover
Logic flaw |
NA |
Demon (@R29k_) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
744 | Interesting find on the Invite link |
Logic flaw |
NA |
Sathvika |
Bug Bounty | 2022-12-02 | 2023-06-13 |
743 | [WRITE-UP] Irremovable comments on the FB Lite app | A story of a simple FB Lite bug that I found just by observation (Bounty: 500 USD) |
Logic flaw |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2022-12-02 | 2023-06-13 |
704 | How I became a millionaire in 3h | Fintech Bug Bounty — Part 1 |
IDOR
Lack of rate limiting
Logic flaw |
NA |
0x4KD (@0x4kd) |
Bug Bounty | 2022-12-12 | 2023-06-13 |
683 | The Bug That Kept On Giving :: PaymentBypass :: Response Manipulation |
Payment bypass
Logic flaw |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-12-16 | 2023-06-13 |
605 | Full Team Takeover |
Broken Access Control
Logic flaw |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
601 | How I Earned $1000 From Business Logic Vulnerability (account takeover) |
Logic flaw
Account takeover |
NA |
andika |
Bug Bounty | 2023-01-10 | 2023-06-13 |
582 | AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass |
Cloud
Logic flaw
CloudTrail bypass |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
537 | Disclosing Facebook page admins by playing a game |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2023-01-28 | 2023-06-13 |
496 | I was able to see likes count even though it was hidden by the victim | YouTube App 16.15.35 |
Logic flaw |
Google (Youtube) |
R ando (@Rando02355205) |
Bug Bounty | 2023-02-05 | 2023-06-13 |
483 | Bypassing API Restrictions for Fun and Profit |
Payment bypass
Logic flaw |
NA |
Arnav Tripathy |
Bug Bounty | 2023-02-07 | 2023-06-13 |
467 | We Hacked GitHub for a Month: Here’s What We Found |
Pre-account takeover
Broken Access Control
Email verification bypass
Logic flaw |
GitHub |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
438 | The Inside Story of Finding a Reverse Transaction Vulnerability in a Financial Application |
Logic flaw
Payment tampering |
NA |
Raja Uzair Abdullah (@UzaiRaja) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
432 | [1500$ Worth — Slack] vulnerability, bypass invite accept process |
Broken Access Control
Logic flaw |
Slack |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-02-20 | 2023-06-13 |
353 | 30-Minute Heist: How I Bagged a $1500 Bounty in Just few Minutes! |
Broken Access Control
Logic flaw |
NA |
Charlie : The Hacker |
Bug Bounty | 2023-03-04 | 2023-06-13 |
335 | Unauthorized access to Codespace secrets in GitHub |
Logic flaw
Broken Access Control
Account takeover |
GitHub |
Ophion Security (@OphionSecurity) |
Bug Bounty | 2023-03-07 | 2023-06-13 |
320 | Improper Authentication in Android App |
Logic flaw
Authentication flaw
HTTP response manipulation |
NA |
oXnoOneXo |
Bug Bounty | 2023-03-10 | 2023-06-13 |
293 | CHECKMATE |
Websockets
Logic flaw |
Chess.com |
Oded Vaanunu |
Bug Bounty | 2023-03-16 | 2023-06-13 |