2456 | How i was able to get Appreciation from the organization of a website just by changing a sign..!!! |
Information disclosure
Source code disclosure |
NA |
Fardeen Ahmed (@fardeenahmed411) |
Bug Bounty | 2021-06-23 | 2023-06-13 |
2441 | Diving into Dependabot along with a bug in npm |
SSRF
RCE |
GitHub |
tyage (@tyage) |
Bug Bounty | 2021-06-27 | 2023-06-13 |
2437 | Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) |
RCE
Insecure deserialization |
NA |
Michael Stepankin (@artsploit) |
Bug Bounty | 2021-06-29 | 2023-06-13 |
2424 | Facebook Email/phone disclosure using Binary search |
Password reset
Information disclosure
Bruteforce |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-07-09 | 2023-06-13 |
2420 | Critical Bug Bounty Reports: Part 1 |
Account takeover
Password reset
RCE
Information disclosure |
NA |
Greg Gibson |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2413 | Forced Browsing to Access Admin Panel |
Forced browsing |
NA |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2405 | Remote code execution in cdnjs of Cloudflare |
RCE
Path traversal |
Cloudflare |
RyotaK (@ryotkak) |
Bug Bounty | 2021-07-16 | 2023-06-13 |
2403 | RCE via WebDav - Power Of PUT |
Default credentials
RCE |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-07-18 | 2023-06-13 |
2395 | Guest Blog Post - Attacking the DevTools |
Browser hacking |
Microsoft |
David Erceg (@david_erceg) |
Bug Bounty | 2021-07-21 | 2023-06-13 |
2376 | Pre-Auth RCE in Moodle Part I - PHP Object Injection in Shibboleth |
RCE
PHP Object Injection |
Moodle |
Johannes Moritz |
Bug Bounty | 2021-07-27 | 2023-06-13 |
2367 | XXE in Public Transport Ticketing Mobile APP |
XXE
RCE |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2021-07-30 | 2023-06-13 |
2363 | From Hobby to Hacking |
Unrestricted file upload
RCE
Missing authentication |
NA |
Muhammad Syahrul Haniawan (@b0x_in) |
Bug Bounty | 2021-07-31 | 2023-06-13 |
2349 | How the use of hidden form fields lead to Email verification bypass |
Email verification bypass
Client-side enforcement of server-side security |
NA |
Yash Swarup (@wazirsec) |
Bug Bounty | 2021-08-03 | 2023-06-13 |
2345 | Do you like to read? I can take over your Kindle with an e-book |
Memory corruption
RCE
Local Privilege Escalation |
Amazon |
Slava Makkaveev |
Bug Bounty | 2021-08-06 | 2023-06-13 |
2338 | CVE-2021-25738 |
RCE |
Kubernetes |
Jordy Versmissen / J0VSEC (@j0v0x0) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2329 | How I found read/write access to the personal data of 3 million users of an E-commerce website? |
IDOR |
NA |
Prashant Singh / SecGeek_one0one |
Bug Bounty | 2021-08-13 | 2023-06-13 |
2314 | A New Attack Surface on MS Exchange Part 1 - ProxyLogon! |
RCE
Privilege escalation |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2021-08-18 | 2023-06-13 |
2311 | How I got RCE In The World Largest Russian Company |
RCE |
Mail.ru |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-20 | 2023-06-13 |
2304 | Zoom RCE from Pwn2Own 2021 |
RCE
Memory corruption |
Zoom |
Thijs Alkemade (@xnyhps) |
Bug Bounty | 2021-08-23 | 2023-06-13 |
2298 | “How Companies Need to Widen There Scopes” |
RCE
Components with known vulnerabilities |
NA |
amnotacat |
Bug Bounty | 2021-08-25 | 2023-06-13 |
2293 | Pwn2Own Vancouver 2021 :: Microsoft Exchange Server Remote Code Execution |
RCE
MiTM |
Microsoft |
Steven Seeley (@steventseeley) |
Bug Bounty | 2021-08-25 | 2023-06-13 |
2286 | Exploiting Devops -Leak Source codes |
Information disclosure |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2021-08-28 | 2023-06-13 |
2283 | Bug Bounty: “My Remote Code Execution” |
Default credentials
RCE |
NA |
0xJin (@0xJin) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2273 | Broken Access Control Leads To Change Of Admin Details |
Privilege escalation
Client-side enforcement of server-side security |
NA |
V3D (@v3d_bug) |
Bug Bounty | 2021-08-31 | 2023-06-13 |
2271 | Dropping root shell in a Crypto Exchange for Fun and Profitn%27t |
RCE |
ChangeNOW |
Nirmal Thapa (@tnirmalz) |
Bug Bounty | 2021-08-31 | 2023-06-13 |