1494 | Security Vulnerability in GitLab: Sending Arbitrary Requests through Jupyter Notebooks |
HTML injection |
GitLab |
Daniel Fürst (@DnlFrst) |
Bug Bounty | 2022-06-07 | 2023-06-13 |
1493 | CVE-2022-26937: Microsoft Windows Network File System NLM Portmap Stack Buffer Overflow |
Buffer Overflow
Memory corruption |
Microsoft |
Yuki Chen (@guhe120) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1492 | Exploiting Amazon active vulnerability |
Payment bypass
Logic flaw |
Amazon |
Benjamin Walter |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1491 | Account Takeover by Chaining Two IDORs |
IDOR
Account takeover |
NA |
Demon (@R29k_) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1490 | Extracting Clear-Text Credentials Directly From Chromium’s Memory |
Browser hacking |
Google (Chromium) |
Zeev Ben Porat |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1489 | De-Anonymization attacks against Proton services |
Privacy issue
Information disclosure
HTML injection
Local Privilege Escalation |
Proton AG |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1488 | Denial of Service Vulnerability in Envoy Proxy – CVE-2022-29225 |
Zip bomb
DoS |
Envoy |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1487 | Autodesk Fusion 360 <= 2.0.12887 “Insert SVG” Blind XXE |
XXE |
Autodesk |
Giulio %27linset%27 Casciaro (@Lins3t) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1486 | Chaining vulnerabilities to criticality in Progress WhatsUp Gold |
SSRF
Local File Disclosure
Information disclosure |
Progress (WhatsUp Gold) |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1485 | CVE-2022-1040 Sophos XG Firewall Authentication bypass |
Authentication bypass
RCE |
Sophos |
Nguyễn Đình Biển (@biennd279) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1484 | How to download eBooks from Google Play Store without paying for them |
Payment bypass
Logic flaw |
Google |
Yess (@Yess_2021xD) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1483 | My first CVE-2022–31289 |
Authentication bypass
403 bypass
HTTP response manipulation |
Sonatype |
Praveen Mali (@pmmali_) |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1482 | ed25519-unsafe-libs |
Cryptographic issues |
NA |
Konstantinos Chalkias |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1481 | A Story of a Bug Found Fuzzing |
Browser hacking
Memory corruption |
Google
Microsoft |
Abdulrhman Alqabandi (@qab) |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1480 | From blind SSRF to localhost dirbusting and asset enumeration |
SSRF |
NA |
Jovan Šikanja (@joshibeast) |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1479 | Same bug different platform |
Logic flaw
Authorization flaw |
Meta / Facebook |
Prajwol Dhungana (@PrajwolDhunga14) |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1478 | How I found a Critical Bug in Instagram and Got 49500$ Bounty From Facebook |
IDOR |
Meta / Facebook |
Neeraj Sharma (@root_n33r4j) |
Bug Bounty | 2022-06-12 | 2023-06-13 |
1477 | Hacking 6.5+ million websites => CVE-2022-29455 (Elementor) |
XSS |
NA |
Rotem Bar (@rotembar) |
Bug Bounty | 2022-06-12 | 2023-06-13 |
1476 | Finding vulnerabilities in curl 7.83.0 without reading a single-line of C code |
SSRF
Information disclosure
HSTS bypass |
Internet Bug Bounty (curl) |
Haxatron (@Haxatron1) |
Bug Bounty | 2022-06-12 | 2023-06-13 |
1475 | Yet another bug into Netfilter |
Memory corruption
Local Privilege Escalation |
Linux Kernel Organization |
Arthur Mongodin |
Bug Bounty | 2022-06-13 | 2023-06-13 |
1474 | Microsoft Azure Synapse Pwnalytics |
Privilege escalation
Cloud |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-06-13 | 2023-06-13 |
1473 | How I was able to see likes and dislikes count which is hidden by victim | YouTube #1 |
Logic flaw
Authorization flaw |
Google |
Jay Jani (@JayJani007) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1472 | 500$ Account Takeover |
Account takeover
Information disclosure
HTTP response manipulation |
Xsolla |
Hemant Kumar |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1471 | Bypassing CSP with dangling iframes |
CSP bypass |
Google
Mozilla |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1470 | SynLapse – Technical Details for Critical Azure Synapse Vulnerability |
Cross-tenant vulnerability
RCE
Cloud |
Microsoft |
Tzah Pahima (@TzahPahima) |
Bug Bounty | 2022-06-14 | 2023-06-13 |