2450 | PII Leakage - Revealing Secrets |
Information disclosure |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-06-25 | 2023-06-13 |
2449 | From Information Disclosure to interesting Privilege Escalation |
Information disclosure
Account takeover
Privilege escalation |
NA |
David Shaul (@dudy2kk) |
Bug Bounty | 2021-06-25 | 2023-06-13 |
2424 | Facebook Email/phone disclosure using Binary search |
Password reset
Information disclosure
Bruteforce |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-07-09 | 2023-06-13 |
2420 | Critical Bug Bounty Reports: Part 1 |
Account takeover
Password reset
RCE
Information disclosure |
NA |
Greg Gibson |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2415 | Part 2: Dive into Zoom Applications |
CSRF
Account takeover
Information disclosure
Session expiration issue
Authorization flaw
Logic flaw |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2404 | IIS-Default-Page-to-Information-Disclosure |
Information disclosure |
NA |
0xdln (@0xdln) |
Bug Bounty | 2021-07-17 | 2023-06-13 |
2399 | Hacking Xiaomi%27S Android Apps - Part 1 |
Android
Information disclosure
Open redirect
Privacy issue |
Xiaomi |
Ameya (@iamTakeMyHand) |
Bug Bounty | 2021-07-19 | 2023-06-13 |
2387 | Not valid bug that leads to us a multiple Valid Report in Facebook |
Information disclosure |
Meta / Facebook |
Kent Jarold Abulag (@wkemenhehehegsg) |
Bug Bounty | 2021-07-25 | 2023-06-13 |
2384 | Bug Chain leads to Mass Account Takeover! |
Information disclosure
Password reset
Account takeover |
NA |
Shubhayu Majumdar (@shubhayu64) |
Bug Bounty | 2021-07-26 | 2023-06-13 |
2375 | Information Disclosure to Account Takeover |
Information disclosure
OAuth
Account takeover
Authentication bypass |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-07-28 | 2023-06-13 |
2370 | Gaining Access To GCP Of Google Stadia — 500$ Bounty |
Information disclosure |
Google |
Sebastien Kaul |
Bug Bounty | 2021-07-29 | 2023-06-13 |
2360 | The journey from Google Honorable Mention to Hall of Fame. |
Referer leakage
Information disclosure
Password reset |
Google |
Akash basnet (@noneofyou007) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2357 | Bug bounty - PHI/PII critical data exposure |
Information disclosure |
NA |
Molx32 |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2350 | How I Scored 1K Bounty Using Waybackurls |
Information disclosure |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2319 | CVE-2021-22929 – Brave Browser 1.27 and below permanently logs the server connection time for all v2 tor domains to ~/.config/BraveSoftware /Brave-Browser/tor/data/tor.log |
Privacy issue
Information disclosure |
Brave Software |
sickcodes (@sickcodes) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2313 | Account Takeover via Access Token Leakage |
IDOR
Information disclosure
Account takeover |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2312 | Disclose WhatsApp Number of Instagram Accounts Despite Setting Set to be Hidden |
Information disclosure
Logic flaw |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2308 | How I was able to get 1000$ bounty from a ds-store file? |
Information disclosure
Debugging enabled |
NA |
Khaled Mohamed (@0xElkomy) |
Bug Bounty | 2021-08-21 | 2023-06-13 |
2302 | By Design: How Default Permissions on Microsoft Power Apps Exposed Millions |
Information disclosure |
Microsoft |
UpGuard Team (@upguard) |
Bug Bounty | 2021-08-23 | 2023-06-13 |
2300 | [$5K] Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO) |
Account takeover
Password reset
Information disclosure |
NA |
Aditya Sharma (@Assass1nmarcos) |
Bug Bounty | 2021-08-24 | 2023-06-13 |
2296 | Vulnerability in Bumble dating app reveals any user%27s exact location |
Information disclosure
Logic flaw |
Bumble |
Robert Heaton (@RobJHeaton) |
Bug Bounty | 2021-08-25 | 2023-06-13 |
2290 | Oauth client secret leak and possible IDOR leading to PII Disclosure |
IDOR
OAuth
Information disclosure |
NA |
Monke (@pmofcats) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2286 | Exploiting Devops -Leak Source codes |
Information disclosure |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2021-08-28 | 2023-06-13 |
2282 | Information disclosure via api misconfiguration |
Information disclosure |
NA |
Rizwan_siddiqui (@Rizwan_SiDdiqu1) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2266 | Hacking Dutch Government For a lousy T-shirt |
IDOR
Information disclosure |
Dutch Government |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2021-09-02 | 2023-06-13 |