4028 | Microsoft Office 365 - Outlook XSS |
XSS |
Microsoft |
Abdulrahman Alqabandi (@Qab) |
Bug Bounty | 2019-07-19 | 2023-06-13 |
4021 | Reflected XSS in Ebay.com |
Reflected XSS |
Ebay |
Sukhmeet Singh (@MadGuyyy) |
Bug Bounty | 2019-07-22 | 2023-06-13 |
4020 | XSS On Twitter [Worth 1120$] |
XSS |
NA |
Bywalks (@bywalkss) |
Bug Bounty | 2019-07-22 | 2023-06-13 |
4010 | Chaining Cache Poisoning To Stored XSS |
Web cache poisoning
Stored XSS |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
4003 | Reposted [2017]: LinkedIn Hacker’s Experience |
Stored XSS |
LinkedIn |
Alexandru Coltuneac (@dekeeu) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
3993 | How I Found XSS By Searching In Shodan |
Reflected XSS |
NA |
D1vy4n5hu 5hukl4 (@justm0rph3u5) |
Bug Bounty | 2019-08-04 | 2023-06-13 |
3992 | Leveraging AngularJS-based XSS to Privilege Escalation |
XSS
Privilege escalation |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2019-08-04 | 2023-06-13 |
3991 | Stored XSS on LaporBug.id |
Stored XSS |
LaporBug.id |
rizal (@sayadarijawa) |
Bug Bounty | 2019-08-05 | 2023-06-13 |
3988 | self XSS to stored XSS [ think out the box] |
Self-XSS
Stored XSS |
TIBCO |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3987 | CRLF injection allow => cookie injection in root domain & xss |
CRLF injection |
Bukalapak |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3984 | Writing my Medium blog to complete account takeover |
Stored XSS
Account takeover |
Medium |
Rotem Reiss (@rotem_reiss) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3979 | Clickjacking DOM XSS on Google.org |
Clickjacking
DOM XSS |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2019-08-12 | 2023-06-13 |
3978 | Reporting - Amazon 1 click device XSS |
XSS |
Amazon |
Sneakerhax (@sneakerhax) |
Bug Bounty | 2019-08-12 | 2023-06-13 |
3975 | BugBounty WriteUp — take attention and get Stored XSS |
Stored XSS |
NA |
Oleksandr Opanasiuk (@Lekssik2) |
Bug Bounty | 2019-08-14 | 2023-06-13 |
3965 | Kaspersky in the Middle – what could possibly go wrong? |
Clickjacking
Universal XSS
MiTM |
Kaspersky |
Wladimir Palant (@WPalant) |
Bug Bounty | 2019-08-19 | 2023-06-13 |
3953 | How i was able to exploit the same endpoint 2 times ( multiple xss & open Redirection on 10 subdomain) |
XSS
Open redirect |
Sanity.io |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2019-08-26 | 2023-06-13 |
3946 | Google Cloud Blog platform vulnerability |
XSS |
Google |
Alexandru Coltuneac (@dekeeu) |
Bug Bounty | 2019-09-01 | 2023-06-13 |
3940 | DOM Based XSS in Private Program |
DOM XSS |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-09-05 | 2023-06-13 |
3939 | Super Glamorous Recon with Intended Functionalities |
SSTI
XSS |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2019-09-06 | 2023-06-13 |
3935 | XSS in Zoho Mail |
XSS |
Zoho |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2019-09-08 | 2023-06-13 |
3931 | H1-4420: From Quiz to Admin - Chaining Two 0-Days to Compromise An Uber Wordpress |
Stored XSS
SQL injection |
Uber |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2019-09-10 | 2023-06-13 |
3910 | Stored XSS on Zendesk via Macro’s PART 2 |
Stored XSS |
Zendesk |
Hariharan.s (@DJHARIZ1) |
Bug Bounty | 2019-09-20 | 2023-06-13 |
3905 | [Bug Bounty] Exploiting Cookie Based XSS by Finding RCE |
Information disclosure
SQL injection
Authentication bypass
Unrestricted file upload
RCE
XSS |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-09-22 | 2023-06-13 |
3902 | ONEPLUS XSS vulnerability in Customer Support Portal |
XSS |
OnePLus |
Mainak Sadhukhan |
Bug Bounty | 2019-09-24 | 2023-06-13 |
3896 | Bug Hunting: Xss On Cookie Popup Warning |
Reflected XSS |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2019-09-30 | 2023-06-13 |