2619 | Remote code execution in Homebrew by compromising the official Cask repository |
RCE |
Homebrew |
RyotaK (@ryotkak) |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2611 | RCE via Internal Access to Adminer Database Management (Critical) |
RCE |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-04-24 | 2023-06-13 |
2605 | CVE-2021-22204 - Recreating a critical bug in ExifTool, no Perl smarts required. |
RCE |
Exiftool |
- |
Bug Bounty | 2021-04-26 | 2023-06-13 |
2603 | WordPress 5.7 XXE Vulnerability |
XXE |
WordPress |
Sonar (@SonarSource) |
Bug Bounty | 2021-04-27 | 2023-06-13 |
2596 | PHP Supply Chain Attack on Composer |
Argument injection
RCE
Supply chain attack
Security code review |
Packagist |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2021-04-29 | 2023-06-13 |
2591 | Password reset code brute-force vulnerability in AWS Cognito |
Password reset
Bruteforce
Rate limiting bypass
Account takeover |
AWS |
Pentagrid (@pentagridsec) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2589 | How I found my first RCE? |
RCE |
NA |
ipanda (@ipanda915) |
Bug Bounty | 2021-05-01 | 2023-06-13 |
2586 | Basic recon to RCE |
Insecure deserialization
RCE |
NA |
Joshua Martinelle (@J0_mart) |
Bug Bounty | 2021-05-02 | 2023-06-13 |
2584 | Finding known exploits for bugbounties. |
RCE |
NA |
ipanda (@ipanda915) |
Bug Bounty | 2021-05-03 | 2023-06-13 |
2583 | Deep Dive into Open Source Bug Bounty |
CSRF |
NA |
Ritik Sahni (@ritiksahni22) |
Bug Bounty | 2021-05-03 | 2023-06-13 |
2582 | Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida |
RCE |
Valve |
Geebz (@Gbps111) |
Bug Bounty | 2021-05-04 | 2023-06-13 |
2581 | ExifTool CVE-2021-22204 - Arbitrary Code Execution |
RCE |
GitLab |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2021-05-04 | 2023-06-13 |
2575 | How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit |
RCE |
Google |
- |
Bug Bounty | 2021-05-05 | 2023-06-13 |
2569 | Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub |
Missing authentication
Forced browsing |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2560 | Counter-Strike Global Offsets: reliable remote code execution |
RCE |
Valve |
brymko (@brymko) |
Bug Bounty | 2021-05-13 | 2023-06-13 |
2556 | 2FA Bypass via Forced Browsing |
MFA bypass |
NA |
Akhil |
Bug Bounty | 2021-05-15 | 2023-06-13 |
2548 | Just Gopher It: Escalating a Blind SSRF to RCE for $15k |
SSRF
RCE |
NA |
SirLeeroyJenkins (@SirLeeroyJenkin) |
Bug Bounty | 2021-05-17 | 2023-06-13 |
2537 | 13 Nagios Vulnerabilities, #7 will SHOCK you! |
RCE
Local Privilege Escalation
XSS
Security code review |
Nagios |
Samir Ghanem (@sam0x21r) |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2536 | 403 Forbidden Bypass |
403 bypass
Forced browsing |
NA |
th3.d1p4k (@DipakPanchal05) |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2518 | Account Takeover via iFrame Injection |
Iframe injection
Account takeover |
NA |
xbforce (@xbforce) |
Bug Bounty | 2021-05-29 | 2023-06-13 |
2508 | Exploiting Open Redirect - Whitelist Bypass Using Salesforce Environment |
Open redirect
Token theft
Salesforce |
NA |
Gaurav Nayak (@4auvar) |
Bug Bounty | 2021-06-02 | 2023-06-13 |
2504 | Android: Exploring vulnerabilities in WebResourceResponse |
Arbitrary file read
Android |
Amazon |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-06-03 | 2023-06-13 |
2495 | Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise |
Password reset
Stored XSS
Privilege escalation
RCE
Security code review |
NA |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2021-06-07 | 2023-06-13 |
2482 | Blind Command Injection - It hurts |
Command injection
RCE |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-06-14 | 2023-06-13 |
2476 | Authentication Bypass | Easy P1 in 10 minutes |
Authentication bypass
Forced browsing |
NA |
Anirudh Makkar (@anirudhmakkar) |
Bug Bounty | 2021-06-16 | 2023-06-13 |