1837 | SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999) |
Local Privilege Escalation |
Microsoft |
Olivier Lyak (@ly4k_) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1836 | WordPress < 5.8.3 - Object Injection Vulnerability |
Object injection
RCE |
WordPress |
Simon Scannell (@scannell_simon) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1835 | Story of critical security flaws I found in Glints |
IDOR
Information disclosure |
Glints |
huli (@aszx87410) |
Bug Bounty | 2022-02-09 | 2023-06-13 |
1834 | Oracle Server Side Request Forgery (SSRF) Metadata |
SSRF |
Oracle |
Lidor Ben Shitrit |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1833 | ICMAD SAP Vulnerabilities (CVE-2022-22536, CVE-2022-22532 & CVE-2022-22533) |
HTTP request smuggling
Memory leak
DoS
Memory corruption |
SAP |
SAP Product Security Response team |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1832 | How I hacked Google to read files from their servers for free! |
Arbitrary file read |
Google |
Harish SG (@CoderHarish) |
Bug Bounty | 2022-02-09 | 2023-06-13 |
1831 | Microsoft Team’s Unpatched URL Spoofing Vulnerability |
URL spoofing |
Microsoft |
Priyank Raval |
Bug Bounty | 2022-02-09 | 2023-06-13 |
1830 | Mindshare: When Mysql Cluster Encounters Taint Analysis |
Memory corruption |
Oracle (MySQL) |
Lucas Leong (@_wmliang_) |
Bug Bounty | 2022-02-10 | 2023-06-13 |
1829 | Subdomain Takeover via Leadpages Services on Tiktok |
Subdomain takeover |
TikTok |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2022-02-11 | 2023-06-13 |
1828 | flashback_connects (Cisco RV340 SSL VPN Unauthenticated Remote Code Execution as root) |
Memory corruption |
Cisco |
Pedro Ribeiro (@pedrib1337) |
Bug Bounty | 2022-02-11 | 2023-06-13 |
1827 | QRCDR ZeroDay Path Traversal Vulnerability |
Path traversal |
NA |
Farhad Karimi (@n0lsec) |
Bug Bounty | 2022-02-11 | 2023-06-13 |
1826 | "Zero-Days" Without Incident - Compromising Angular via Expired npm Publisher Email Domains |
Supply chain attack |
GitHub |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2022-02-11 | 2023-06-13 |
1825 | A tale of 0-Click Account Takeover and 2FA Bypass. |
Account takeover
Password reset
MFA bypass |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2022-02-12 | 2023-06-13 |
1824 | Broken Link Hijacking - Mr. User-Agent |
Broken link hijacking |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-02-13 | 2023-06-13 |
1823 | How i made 15k$ from Remote Code Execution Vulnerability |
Code injection
RCE
Self-XSS |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2022-02-13 | 2023-06-13 |
1822 | Hacking AWS Cognito Misconfiguration to Zero Click Account Takeover |
AWS misconfiguration
Account takeover |
NA |
Preetham Bomma (@cyber01_) |
Bug Bounty | 2022-02-14 | 2023-06-13 |
1821 | My First Bounty and How I Got It |
Subdomain takeover |
NA |
Aneesha D (@interc3pt3r) |
Bug Bounty | 2022-02-14 | 2023-06-13 |
1820 | BigQuery SQL Injection Cheat Sheet |
SQL injection |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2022-02-14 | 2023-06-13 |
1819 | Advisory: Western Digital My Cloud Pro Series PR4100 RCE |
RCE
OS command injection |
Western Digital |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1818 | Static Taint Analysis Using Binary Ninja: A Case Study Of MySQL Cluster Vulnerabilities |
Memory corruption |
Oracle (MySQL) |
Reno Robert (@renorobertr) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1817 | Trim private live videos and access them (Meta bug bounty) |
IDOR |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1816 | Hunting for bugs in VMware: View Planner and vRealize Business for Cloud |
RCE |
VMware |
Mikhail Klyuchnikov (@__Mn1__) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1815 | Bug Report; Bypassing Weekly Limits In Basic (Free) LinkedIn Account |
Logic flaw |
LinkedIn |
Ashok Acharya |
Bug Bounty | 2022-02-16 | 2023-06-13 |
1814 | Hacked Dutch Government Website. All I got was this l̶o̶u̶s̶y̶ cool T-Shirt. |
Information disclosure |
Dutch Government |
Romesh chander |
Bug Bounty | 2022-02-16 | 2023-06-13 |
1813 | My First Reflected XSS Bug Bounty — Google Dork — $xxx |
Reflected XSS |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2022-02-16 | 2023-06-13 |