1623 | Multiple Vulnerabilities in Cisco Expressway |
Memory leak
Exposed administrative interface
STUN
TURN |
Cisco |
Christian Mehlmauer (@firefart) |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1622 | CVE-2022-26133 - Bitbucket Data Center - Java Deserialization Vulnerability |
Insecure deserialization |
Atlassian |
Benny Jacob (@bennyyjacob) |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1621 | Prototype Pollution in fast-xml-parser |
Prototype pollution |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1620 | Crazy Simple Insecure Design & 300$ Bounty! |
IP grabbing |
NA |
Saransh Saraf (@mr23r0) |
Bug Bounty | 2022-04-15 | 2023-06-13 |
1618 | How I was able to see likes and dislikes count even though is hidden by victim | YouTube #4 |
Broken Access Control |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-04-15 | 2023-06-13 |
1617 | How we spoofed ENS domains for $15k |
Homograph attack |
ENS |
Hacxyk. (@Hacxyk) |
Bug Bounty | 2022-04-15 | 2023-06-13 |
1616 | XSLeaking with my best bud SOP |
Information disclosure |
Microsoft |
Ha Anh Hoang |
Bug Bounty | 2022-04-15 | 2023-06-13 |
1615 | Full Account Takeover via Open Redirection |
Open redirect
Token leak
Account takeover
OAuth |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-04-17 | 2023-06-13 |
1614 | SQL Injection in Harvard’s Subdomain |
SQL injection |
Harvard |
Bibek Neupane (@nb1b3k) |
Bug Bounty | 2022-04-17 | 2023-06-13 |
1612 | Palisade identifies Wormable Cross-Site Scripting Vulnerability affecting Rarible’s NFT Marketplace |
XSS |
Rarible |
Palissade (@PalisadeLLC) |
Bug Bounty | 2022-04-18 | 2023-06-13 |
1611 | Adobe Acrobat hollowing out same-origin policy |
XSS
SOP bypass
Open redirect
postMessage |
Adobe |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-04-19 | 2023-06-13 |
1610 | AWS%27s Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation |
Privilege escalation
Container escape |
AWS |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-04-19 | 2023-06-13 |
1609 | CVE-2022-21449: Psychic Signatures in Java |
Signature bypass
Cryptographic issues |
Oracle |
Neil Madden (@neilmaddog) |
Bug Bounty | 2022-04-19 | 2023-06-13 |
1608 | Exploiting a File Upload Vulnerability — A Directory Traversal Attack |
Unrestricted file upload
Path traversal |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-04-20 | 2023-06-13 |
1607 | Gaining Unlimited access to graph AuditLogs endpoint using complex filters with non-privileged user account |
Information disclosure
Privilege escalation |
Microsoft |
Joosua Santasalo (@SantasaloJoosua) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1606 | Open Redirection into Bentley System |
XSS |
Bentley Systems |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1605 | Smashing the Modern Web Tech Stack — Part 1: The Evolving Threat Landscape in 2022 and DOM-based XSS in Cloud-Native React Apps. |
Open redirect
XSS |
NA |
MalwareJoe |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1604 | Security issues with cloudflare/odoh-server-go and the ODoH RFC draft |
SSRF |
Cloudflare |
Frans Rosén (@fransrosen) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1603 | Adventures Into The MeowCorp Bug Bounty Program |
Information disclosure
Weak credentials
SSRF
.git folder disclosure
RCE |
NA |
Nirmal Thapa (@tnirmalz) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1602 | How I Bypassed 2FA while Resetting Password |
MFA bypass
Password reset |
NA |
Sufiyan Gouri (@gouri_sufyan) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1601 | How I got Apple Hall Of Fame ! |
Content injection |
Apple |
shubhdeep (@Shubhdeeppp) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1600 | EJS, Server side template injection RCE (CVE-2022-29078) - writeup |
SSTI
RCE |
ejs
NetApp |
Eslam Salem (@net_code) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1599 | Unlock any blur text/picture without membership/subscription on Scribd.com |By Neuchi |
Payment bypass
Logic flaw |
Scribd.com |
Neil Neuchi |
Bug Bounty | 2022-04-25 | 2023-06-13 |
1598 | Fuzzing and credentials leakage..awesome bug hunting writeup |
Hardcoded credentials
Information disclosure |
NA |
Abdalrahman Alshammas |
Bug Bounty | 2022-04-25 | 2023-06-13 |
1597 | Package Planting: Are You [Unknowingly] Maintaining Poisoned Packages? |
Logic flaw |
GitHub |
Yakir Kadkoda |
Bug Bounty | 2022-04-26 | 2023-06-13 |