1469 | Cryptographic Side-Channels (Timing Leaks) in JSBN |
Cryptographic issues
Side-channel attack
Timing attack |
Xfinity Opensource |
Soatok (@SoatokDhole) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1468 | 403 bypass on a fortune 100 financial institution (P3) |
Information disclosure
Authorization flaw
Forced browsing |
NA |
Damaidec |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1467 | Zimbra Email - Stealing Clear-Text Credentials via Memcache injection |
Memcache injection
CRLF injection |
Zimbra |
Sonar (@SonarSource) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1466 | 2FA Bypass via Basic Authentication on private bug bounty program |
MFA bypass |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1465 | Automating reflected XSS with burp-suite Intruder |
Reflected XSS |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1464 | Hertzbleed Attack |
Side-channel attack
Hardware hacking
Cryptographic issues |
Intel
Cloudflare
Microsoft |
Yingchen Wang (@YingchenWang96) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1463 | [BugTales] UnZiploc: From 0-click To Platform Compromise |
Memory corruption
Logic flaw
RCE
Local Privilege Escalation |
Huawei |
Daniel Komaromy (@kutyacica) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1462 | Privilege Escalation in AKS Clusters |
Privilege escalation |
Microsoft |
Anneke Breust |
Bug Bounty | 2022-06-15 | 2023-06-13 |
1461 | Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu |
Hardware hacking
Memory corruption |
Google |
Frédéric Basse (@FredoBasse) |
Bug Bounty | 2022-06-15 | 2023-06-13 |
1460 | Amazon Linux "log4j hotpatch" <1.3-5 local privilege escalation to root (race condition) |
Local Privilege Escalation |
Amazon |
Justin Steven (@justinsteven) |
Bug Bounty | 2022-06-15 | 2023-06-13 |
1459 | CVE-2022-23088: Exploiting A Heap Overflow In The Freebsd Wi-fi Stack |
Memory corruption
RCE |
FreeBSD Security Team |
m00nbsd (@m00nbsd) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1458 | Proofpoint Discovers Potentially Dangerous Microsoft Office 365 Functionality that can Ransom Files Stored on SharePoint and OneDrive |
Logic flaw |
Microsoft |
Proofpoint (@proofpoint) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1457 | XSS Blind Stored at Asset Domain Android Apps TikTok |
Stored XSS |
TikTok |
Aidil Arief |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1456 | The Android kernel mitigations obstacle race |
Memory corruption
Android |
Qualcomm |
Man Yue Mo (@mmolgtm) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1455 | Chaining MFA-Enabled IAM Users with IAM Roles for Potential Privilege Escalation in AWS |
Privilege escalation |
AWS |
Jason Kao |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1454 | CSRF leads to account takeover in Yahoo! |
CSRF
Account takeover |
Yahoo! / Verizon Media |
Retr02332 (@Retr02332) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1453 | That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability |
RCE |
Microsoft |
Gabriel Sztejnworcel (@sztejnworcel) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1452 | How I was able to see likes and dislikes count which is hidden by victim | YouTube #2 |
Logic flaw
Authorization flaw |
Google |
Jay Jani (@JayJani007) |
Bug Bounty | 2022-06-17 | 2023-06-13 |
1451 | Hacking a NFT Platform |
SSRF |
NA |
Muhammad Abdullah |
Bug Bounty | 2022-06-17 | 2023-06-13 |
1450 | How I hacked one of the biggest Airline in the world |
IDOR
Account takeover
Authorization flaw |
NA |
Dali Jandro (@Sazouki_) |
Bug Bounty | 2022-06-18 | 2023-06-13 |
1449 | Personal Access Token Disclosure in Asana Desktop Application |
Information disclosure
Hardcoded credentials |
Asana |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2022-06-18 | 2023-06-13 |
1448 | Account Takeover by OTP bypass |
Information disclosure
Client-side enforcement of server-side security
OTP bypass
Account takeover |
NA |
Vaibhav Kumar Srivastava |
Bug Bounty | 2022-06-19 | 2023-06-13 |
1447 | Every XSS is different |
XSS |
NA |
Leonardo |
Bug Bounty | 2022-06-20 | 2023-06-13 |
1445 | Hacking into the worldwide Jacuzzi SmartTub network |
SPA
Android
JWT
Privilege escalation
Mass assignment |
Jacuzzi Group
SmartTub |
Eaton Z. (@XeEaton) |
Bug Bounty | 2022-06-20 | 2023-06-13 |
1444 | XSS Vulnerability in IBM Content Navigator (CVE-2020-4757) |
XSS |
IBM |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-06-21 | 2023-06-13 |