182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
180 | Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2 |
Local Privilege Escalation
TOCTOU
Arbitrary file write |
Docker |
Eviatar Gerzi |
Bug Bounty | 2023-04-19 | 2023-06-13 |
178 | Vulnerability Spotlight: CVE-2023-0264 |
OpenID Connect
OAuth
Authentication flaw
Privilege escalation
Security code review |
Keycloack |
Timo Müller (@mtimo44) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
173 | The Fuzzing Guide to the Galaxy: An Attempt with Android System Services |
Android
Fuzzing
Heap overflow
Integer overflow
Out-of-bounds Write
Memory corruption
Local Privilege Escalation |
Samsung |
Anthony Remy |
Bug Bounty | 2023-04-20 | 2023-06-13 |
169 | CVE-2023-23525: Get Root via A Fake Installer |
Local Privilege Escalation |
Apple (macOS) |
Mickey Jin (@patch1t) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
164 | Stealing GitHub staff%27s access token via GitHub Actions |
CI/CD
Token leak
Privilege escalation
Supply chain attack |
GitHub |
RyotaK (@ryotkak) |
Bug Bounty | 2023-04-22 | 2023-06-13 |
150 | Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587) |
TOCTOU
NULL pointer dereference
Arbitrary file write
Local Privilege Escalation |
Avast |
Denis Skvortcov (@Denis_Skvortcov) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
146 | Privilege Escalation in Microsoft Windows |
Local Privilege Escalation |
Microsoft (Windows) |
Tobias Neitzel (@qtc_de) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
136 | AWS Identity Center (formerly known as AWS SSO): A Guide to Privilege Escalation and Identity and Access Management |
Privilege escalation
Cloud |
AWS |
Jason Kao |
Bug Bounty | 2023-05-01 | 2023-06-13 |
132 | Securing Databricks cluster init scripts |
Privilege escalation
Cloud |
Databricks |
Elia Florio |
Bug Bounty | 2023-05-02 | 2023-06-13 |
126 | CVE-2023-25394 - VideoStream Local Privilege Escalation |
Local Privilege Escalation |
Videostream |
Dan Revah (@danrevah) |
Bug Bounty | 2023-05-03 | 2023-06-13 |
124 | Privilege Escalations through Integrations |
Privilege escalation
Amazon cognito misconfiguration
JWT
Account takeover |
NA |
Colin McQueen |
Bug Bounty | 2023-05-04 | 2023-06-13 |
120 | Bullied by Bugcrowd over Kape CyberGhost disclosure |
Local Privilege Escalation
OS command injection
Security code review |
Kape (CyberGhost) |
Ceri Coburn (@_ethicalchaos_) |
Bug Bounty | 2023-05-05 | 2023-06-13 |
111 | Escaping Parallels Desktop with Plist Injection |
Local Privilege Escalation
Plist injection
TOCTOU |
Parallels |
kn32 |
Bug Bounty | 2023-05-08 | 2023-06-13 |
105 | From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API |
Privilege escalation
NTLM |
Microsoft (Outlook) |
Ben Barnea (@nachoskrnl) |
Bug Bounty | 2023-05-10 | 2023-06-13 |
103 | What is kong & why we’re relying on it |
RCE
Sandbox escape
Authentication bypass
Hardcoded credentials
Broken Access Control
Privilege escalation
JWT |
Konga |
Laluka (@TheLaluka) |
Bug Bounty | 2023-05-10 | 2023-06-13 |
102 | Hacking Chess.com: My Journey to Unlock Premium Bots on the Android App |
Android
Privilege Escalation |
Chess.com |
Fr4 (@_icebre4ker_) |
Bug Bounty | 2023-05-10 | 2023-06-13 |
96 | CS:GO: From Zero to 0-day |
Game hacking
RCE
Memory corruption
Arbitrary file download
Arbitrary file write
DLL Hijacking
Privilege Escalation |
Valve (CS:GO) |
Felipe |
Bug Bounty | 2023-05-13 | 2023-06-13 |
95 | CVE-2023-26818 - Bypass TCC with Telegram in macOS |
TCC bypass
Local Privilege Escalation |
Apple (macOS) |
Dan Revah (@danrevah) |
Bug Bounty | 2023-05-15 | 2023-06-13 |
92 | Finding and reporting a Gatekeeper bypass exploit with help from Mac Monitor |
GateKeeper bypass
Local Privilege Escalation
MacOS |
Apple (macOS) |
Brandon Dalton (@PartyD0lphin) |
Bug Bounty | 2023-05-15 | 2023-06-13 |
90 | Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586) |
TOCTOU
Arbitrary file write
Local Privilege Escalation |
Avast
NortonLifeLock |
Denis Skvortcov (@Denis_Skvortcov) |
Bug Bounty | 2023-05-15 | 2023-06-13 |
84 | From DA to EA with ESC5 |
Active Directory Privilege Escalation
Internal pentest |
NA |
Andy Robbins (@_wald0) |
Bug Bounty | 2023-05-17 | 2023-06-13 |
82 | LOLBINed — Finding “LOLBINs” In AV Uninstallers |
Local Privilege Escalation |
Kaspersky
F-Secure
Trend Micro
McAfee |
Nasreddine Bencherchali (@nas_bench) |
Bug Bounty | 2023-05-17 | 2023-06-13 |
81 | DLL Hijacking Strikes Back: Exploiting Windows on ARM RDP Client (CVE-2023-24905) |
DLL Hijacking
Local Privilege Escalation |
Microsoft (Windows) |
Dor Dali |
Bug Bounty | 2023-05-17 | 2023-06-13 |
62 | Tampering with Conditional Access Policies Using Azure AD Graph API |
Cloud
Privilege escalation |
Microsoft (Azure) |
Secureworks Counter Threat Unit (@Secureworks) |
Bug Bounty | 2023-05-23 | 2023-06-13 |