1758 | How I managed to make a DDoS attack by exploiting a company’s service — Bug Bounty |
DoS |
NA |
Mr Empy (@mr_empy) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1757 | Log4shell in google $1337.00 |
Log4shell
RCE |
Google |
amnotacat (@Amnotacat1) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1756 | Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities |
Privilege escalation
Container escape
Kubernetes |
Google |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1755 | Oracle Access Manager Pre-Auth RCE (CVE-2021–35587 Analysis) |
RCE |
Oracle |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1754 | SSD Advisory – NETGEAR DGND3700v2 PreAuth Root Access |
Authentication bypass
OS command injection
RCE |
Netgear |
- |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1753 | Demographic Misconfiguration on Facebook live |
Logic flaw
Authorization flaw |
Meta / Facebook |
Prajwol Dhungana (@PrajwolDhunga14) |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1751 | Escalating from Logic App Contributor to Root Owner in Azure |
Privilege escalation |
Microsoft |
Josh Magri (@passthehashbrwn) |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1749 | Rate Limit Bypass at Readme.com |
Lack of rate limiting
Password reset |
Readme.com |
Girishbo |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1747 | CVE-2022-24696 – Glance By Mirametrix Privilege Escalation |
Local Privilege Escalation |
Lenovo |
Oddvar Moe (@Oddvarmoe) |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1746 | How Did I Leak 5.2k Customer Data From a Large Company? (via Broken Access Control) |
Broken Access Control |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1745 | I have Found Microsoft Subdomain Website database list, database username, password |
Information disclosure |
Microsoft |
Bot Ami (@Botami143) |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1744 | I can see the dislikes count even though is hidden by YouTube | YouTube ($500) |
Broken Access Control
IDOR |
NA |
R ando (@Rando02355205) |
Bug Bounty | 2022-03-12 | 2023-06-13 |
1743 | XSS through base64 encoded JSON |
XSS |
NA |
Aman Pareek (@aman_notsogreat) |
Bug Bounty | 2022-03-12 | 2023-06-13 |
1742 | A Tale of Open Redirection to Stored XSS |
Stored XSS
Open redirect |
NA |
Tushar Sharma (@tusharSharma_0) |
Bug Bounty | 2022-03-12 | 2023-06-13 |
1741 | Open Redirect via Sendgrid Email Misconfiguration |
Open redirect |
NA |
Rifqi Hilmy Zhafrant |
Bug Bounty | 2022-03-13 | 2023-06-13 |
1740 | How I bypassed disable_functions in php to get a remote shell |
RCE |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2022-03-13 | 2023-06-13 |
1739 | Party time: Injecting code into Teleparty extension |
HTML injection
Open redirect
Browser extension hacking |
Teleparty |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1737 | How I access other domains in infinityfree.net using Directory Traversal |
Directory traversal |
InfinityFree |
Kurt Russelle Marmol |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1736 | SQL Injection at Spotify |
SQL injection |
Spotify |
Eslam Akl (@eslam3kll) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1735 | Achieving Remote Code Execution via Unrestricted File Upload |
Unrestricted file upload
RCE |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1734 | From Recon via Censys and DNSdumpster, to Getting P1 by Login Using Weak Password – “password” |
WAF bypass
Weak credentials |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1733 | How a macOS bug could have allowed for a serious phishing attack against users |
MacOS
Phishing |
Apple |
Guilherme Rambo (@_inside) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1732 | My First Bug on VDP & BBP - Bug Bounty |
Stored XSS |
NA |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1731 | CVE-2020-24427: Adobe Reader CJK Codecs Memory Disclosure Vulnerability |
Memory disclosure |
Adobe |
Haboob Research Team (@HaboobSa) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1730 | CVE-2022-22616: Simple way to bypass GateKeeper, hidden for years |
Local Privilege Escalation
GateKeeper bypass
MacOS |
Apple |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-03-15 | 2023-06-13 |