1729 | How I managed to trigger XSS automatically to get critical account takeover |
Stored XSS |
NA |
c4rrilat0r (@c4rrilat0r) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1728 | Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582) |
Arbitrary file write |
Apple |
Richard Warren (@buffaloverflow) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1727 | Securing Developer Tools: Git Integrations |
Local Privilege Escalation |
Microsoft
JetBrains
GitHub |
Sonar (@SonarSource) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1726 | SSD Advisory – Exchange Server GetWacInfo Information Disclosure Vulnerability |
XXE
Information disclosure |
Microsoft |
Alex Birnberg (@alexbirnberg) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1725 | How I was able to find 50+ Cross-site scripting (XSS) Security Vulnerabilities on Bugcrowd Public Program? |
XSS |
NA |
akshal(tojojo) |
Bug Bounty | 2022-03-16 | 2023-06-13 |
1724 | Git honours embedded bare repos, and exploitation via core.fsmonitor in a directory%27s .git/config affects IDEs, shell prompts and Git pillagers |
RCE |
GitHub
Microsoft
JetBrains |
Justin Steven (@justinsteven) |
Bug Bounty | 2022-03-16 | 2023-06-13 |
1723 | From XSS to RCE (dompdf 0day) |
XSS
RCE |
NA |
Positive Security (@positive_sec) |
Bug Bounty | 2022-03-16 | 2023-06-13 |
1722 | Parameter Pollution - Zero Day |
HTTP parameter pollution |
Discourse |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-03-17 | 2023-06-13 |
1721 | My First Blind SQL Injection |
SQL injection |
NA |
T VAMSHI |
Bug Bounty | 2022-03-17 | 2023-06-13 |
1720 | Abusing Azure Hybrid Workers for Privilege Escalation – Part 1 |
Privilege escalation |
Microsoft (Azure) |
Josh Magri (@passthehashbrwn) |
Bug Bounty | 2022-03-17 | 2023-06-13 |
1719 | Abusing Arbitrary File Deletes To Escalate Privilege And Other Great Tricks |
Local Privilege Escalation |
Microsoft (Windows) |
Abdelhamid Naceri |
Bug Bounty | 2022-03-17 | 2023-06-13 |
1718 | Bypass confirmation to add payment method. |
Email verification bypass
Logic flaw |
NA |
Yaj Desu |
Bug Bounty | 2022-03-18 | 2023-06-13 |
1717 | For the first Bounty, it takes a few challenging months, but only a few days for the second. |
Old components with known vulnerabilities |
NA |
Aneesha D (@interc3pt3r) |
Bug Bounty | 2022-03-18 | 2023-06-13 |
1716 | Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors |
IDOR |
Microsoft |
Meareg |
Bug Bounty | 2022-03-18 | 2023-06-13 |
1715 | Adobe bug bounty using IDOR, Confidential data leaks |
IDOR |
Adobe |
Debprasad Banerjee |
Bug Bounty | 2022-03-19 | 2023-06-13 |
1714 | Files.app Symbolic Link Following |
iOS |
Apple |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-03-19 | 2023-06-13 |
1713 | CVE-2022-0337 System environment variables leak on Google Chrome, Microsoft Edge and Opera |
Browser hacking |
Google
Microsoft
Opera |
Maciej Pulikowski (@pulik_io) |
Bug Bounty | 2022-03-19 | 2023-06-13 |
1712 | Bug Bounty catches part -1 |
Authentication bypass
Information disclosure
Broken Access Control |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-20 | 2023-06-13 |
1711 | Broken session control leads to access private videos using the shared link even after revoking the access for specific time!! — #GoogleVRP |
Broken Access Control |
Google |
Naveenroy |
Bug Bounty | 2022-03-20 | 2023-06-13 |
1710 | ($$$) Broken Authentication and IDOR at [REDACTED] |
IDOR |
NA |
Rizaldi Wahaz (@wah_haz) |
Bug Bounty | 2022-03-21 | 2023-06-13 |
1709 | Targeting Visual Studio Code for macOS: File Discovery and a TCC bypass (kinda) |
Local Privilege Escalation
TCC bypass
MacoS |
Apple
Microsoft |
Alfie Champion (@ajpc500) |
Bug Bounty | 2022-03-21 | 2023-06-13 |
1708 | iTop – Template Injection inside customer Portal |
SSTI
RCE |
Combodo (iTop) |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2022-03-21 | 2023-06-13 |
1707 | Google Maps API Key Unauthorized Use Case |
Information disclosure |
NA |
Dan Barros |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1706 | Story about more than 3.5 million PII leakage in Yahoo!!! |
IDOR
Information disclosure
iOS |
Yahoo! / Verizon Media |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1705 | Basic recon to RCE II |
RCE |
NA |
Joshua Martinelle (@J0_mart) |
Bug Bounty | 2022-03-22 | 2023-06-13 |