1785 | Piercing the Cloud Armor - The 8KB bypass in Google Cloud Platform WAF |
WAF bypass |
Google |
Kloudle (@Kloudleinc) |
Bug Bounty | 2022-02-24 | 2023-06-13 |
1783 | Bypassing default visibility for newly-added email in Facebook(Part I - Submitting I.D) |
Logic flaw |
Meta / Facebook |
Kent Jarold Abulag (@wkemenhehehegsg) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1782 | A Weird Price Tampering Vulnerability |
Payment tampering
Logic flaw |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1781 | Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager |
Authentication bypass
RCE
SSRF
Path traversal |
VMware |
Egor Dimitrenko (@elk0kc) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1780 | SSRF & LFI In Uploads Feature |
SSRF
LFI
HTML injection |
NA |
Raymond Lind |
Bug Bounty | 2022-02-26 | 2023-06-13 |
1779 | CVE-2022-22947: SpEL Casting And Evil Beans |
RCE
Java Beans |
NA |
Wyatt Dahlenburg (@wdahlenb) |
Bug Bounty | 2022-02-26 | 2023-06-13 |
1778 | Hacking Subscription Plans for free service. |
Payment bypass
OTP bypass |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2022-02-27 | 2023-06-13 |
1777 | BrokenPrint: A Netgear stack overflow |
Memory corruption
RCE |
Netgear |
Alex Plaskett (@alexjplaskett) |
Bug Bounty | 2022-02-28 | 2023-06-13 |
1776 | Pwning a Server using Markdown |
LFI
RCE |
Hashnode |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2022-02-28 | 2023-06-13 |
1775 | HDiff: A Semi-automatic Framework for Discovering Semantic Gap Attack in HTTP Implementations |
HTTP request smuggling
DoS
Semantic gap attacks |
NA |
Kaiwen Shen (@m0xiaoxi) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1774 | Password Reset to Admin Access |
Account takeover
Authentication bypass
Password reset |
NA |
Jesse Clark (@Hogarth45_) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1773 | Skype extension: All functionality broken? Still exploitable! |
Information disclosure
Privacy issue |
Microsoft |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1772 | [ Directory Traversal attack ] How did I find it using GitHub |
Information disclosure
Path traversal |
NA |
Fenrir (@leetibrahim) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1771 | webOS Revisited - Even More Mistaken Identities |
Local Privilege Escalation
Browser hacking |
LG |
Andreas Lindh (@addelindh) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1770 | CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO |
Stored XSS
Account takeover |
Apache |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1769 | IDOR in support.mozilla.org through Code Review |
IDOR |
Mozilla |
Brandon Roldan |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1768 | Moodle 2nd Order Sqli |
SQL injection |
Moodle |
mufinnnnnnn (@mufinnnnnnn) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1767 | 4300$ Instagram IDOR Bug (2022) |
IDOR |
Meta / Facebook |
Nawaf Alkhaldi (@nvmeeet) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1766 | CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED) |
Username enumeration
GraphQL |
GitLab |
Jacob Baines (@junior_baines) |
Bug Bounty | 2022-03-03 | 2023-06-13 |
1764 | How I Hacked A Crypto Company And Could Steal 1 Million Dollars Worth of Bitcoin |
Path traversal |
NA |
zoid (@z0idsec) |
Bug Bounty | 2022-03-05 | 2023-06-13 |
1763 | WhatsApp Bug Bounty: Bypassing biometric authentication using voip |
Authentication bypass |
Meta / Facebook |
Arvind (@ar_arv1nd) |
Bug Bounty | 2022-03-05 | 2023-06-13 |
1762 | Some critical vulnerabilities found with passive analysis on bug bounty programs explained |
Information disclosure
Logic flaw |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1761 | The Bad Twin: a peculiar case of JWT exploitation scenario |
Account takeover |
NA |
Sandh0t (@sandh0t) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1760 | AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service |
Cross-tenant vulnerability
Account takeover |
Microsoft |
Yanir Tsarimi (@Yanir_) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1759 | Circumventing Browser Security Mechanisms For SSRF |
SSRF
XSS |
NA |
HTTPVoid (@httpvoid0x2f) |
Bug Bounty | 2022-03-08 | 2023-06-13 |