2245 | Full structure takeover to many brands of company |
Directory listing
Information disclosure |
NA |
Abdelrahman Khaled |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2243 | 5 Different Vulnerabilities in Google’s Threadit |
DOM XSS
Clickjacking
Privilege escalation
Information disclosure |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2240 | Facebook email disclosure and account takeover |
Information disclosure
Account takeover |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2237 | GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink |
Logic flaw
Information disclosure |
GitHub |
Justin Steven (@justinsteven) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2220 | A Facebook bug that exposes email/phone number to your friends |
Information disclosure
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2213 | From Google Dorking to Information Disclosure |
Information disclosure
Missing authentication |
NA |
MikeChan |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2212 | From phpinfo page to many P1 bugs and RCE. [Symfony] |
File disclosure
Information disclosure
RCE |
NA |
Abdelrahman Khaled |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2211 | A small change, and things go in your hand : Story of a $250 bounty |
Information disclosure |
NA |
Fardeen Ahmed (@fardeenahmed411) |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2209 | Chaining bugs for better bounties |
SSRF
XSS
Information disclosure |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-09-19 | 2023-06-13 |
2203 | A fever Worth 750$- [Accessing Private Projects ] |
IDOR
Information disclosure |
Mozilla |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2194 | Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program |
Information disclosure
Local Privilege Escalation
Privacy issue |
Apple |
Denis Tokarev / illusionofchaos |
Bug Bounty | 2021-09-24 | 2023-06-13 |
2180 | Expect The Unexpected: Discovering fresh ZeroDay for Bounty |
Logic flaw
Information disclosure |
NA |
Sina Kheirkhah (@SinSinology) |
Bug Bounty | 2021-09-30 | 2023-06-13 |
2169 | How I got access to many PIIs through a source code leak |
Information disclosure |
NA |
Supras (@LdrTom) |
Bug Bounty | 2021-10-05 | 2023-06-13 |
2162 | Power of Your Own Wordlist — Fuzz for Log File Leads to Information Leakage |
Information disclosure |
NA |
MikeChan |
Bug Bounty | 2021-10-09 | 2023-06-13 |
2154 | Pulse Secure version number disclosure in error messages |
Information disclosure |
Pulse Secure |
Mehdi Alouache |
Bug Bounty | 2021-10-12 | 2023-06-13 |
2141 | The Speckle Umbrella story — part 2 |
Information disclosure
Logic flaw |
Google |
Imre Rad (@ImreRad) |
Bug Bounty | 2021-10-18 | 2023-06-13 |
2123 | An Effective 5 min recon leads to a Hall of Fame |
Information disclosure |
NA |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-10-26 | 2023-06-13 |
2112 | How I was able to access a properly Configured S3 Bucket |
Leaked AWS keys
Information disclosure |
NA |
Pawan Chhabria (@heybenchmarkkk) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2111 | One misconfiguration to rule them all |
Information disclosure
Debug mode enabled |
NA |
Sushant Soni (@sushantsoni5392) |
Bug Bounty | 2021-10-29 | 2023-06-13 |
2099 | 4 Crits in 48 hours: Unicorn Programs |
Privilege escalation
Information disclosure
IDOR |
NA |
Monke (@pmofcats) |
Bug Bounty | 2021-11-06 | 2023-06-13 |
2093 | 400$ Bounty again using Google Dorks |
Directory listing
Information disclosure |
NA |
Haris M (@hrsm321) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
2086 | From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy |
Broken Access Control
Information disclosure
IDOR
HTML injection |
Udemy |
Mostafa Mamdoh |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2084 | How I got $200 in 30 Seconds. |
Information disclosure |
NA |
Yash__ HackZ (@HackzYash) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2080 | Exploiting CSP in Webkit to Break Authentication & Authorization |
Information disclosure
CSP leak
Account takeover |
Apple |
Sachin Thakuri (@sachinnthakuri) |
Bug Bounty | 2021-11-13 | 2023-06-13 |
2078 | How I Found P1 bug Due to Sensitive data exposure And Earn $$$$ |
Information disclosure |
NA |
Piyush shukla (@PiyushShukla__) |
Bug Bounty | 2021-11-15 | 2023-06-13 |