1443 | Widespread prototype pollution gadgets |
Prototype pollution |
NA |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2022-06-21 | 2023-06-13 |
1442 | Exploiting vulnerabilities in iOS Application |
IDOR
Bruteforce
Lack of rate limiting
Account takeover
iOS |
NA |
Raj Singh Chauhan (@raj_singh_ch) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1440 | We were vulnerable - how a security company could have vulns |
Broken Access Control
Authorization flaw
Information disclosure |
Volkis |
Soman Verma |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1439 | Exploiting Bitdefender Antivirus: RCE from any website |
RCE
Command injection |
Bitdefender |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1438 | Filesatck Upload Advisory Summary |
XSS |
Filestack |
Carlos Yanez |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1437 | Lock Screen Bypass Exploit of Android Devices (CVE-2022–20006) |
Authentication bypass
Lock screen bypass |
Google |
Joshua Nearchos |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1436 | CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed) |
Argument injection |
WatchGuard |
Jake Baines (@Junior_Baines) |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1435 | Pwn2Own 2021 Microsoft Exchange Exploit Chain |
SSRF
RCE |
Microsoft |
Rskvp93 (@rskvp93) |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1434 | Miracle - One Vulnerability To Rule Them All |
Insecure deserialization
SSRF
RCE |
Oracle |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1433 | An Out Of Scope domain Leads To a Critical Bug[$1500] |
Authorization flaw
Broken Access Control |
NA |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2022-06-24 | 2023-06-13 |
1432 | Moderation Filter Bypass in support.mozilla.org |
Logic flaw |
Mozilla |
tomorrowisnew (@tomorrowisnew_) |
Bug Bounty | 2022-06-25 | 2023-06-13 |
1431 | mysqlnd/pdo password buffer overflow leading to RCE (CVE 2022-31626) |
Buffer Overflow
Memory corruption |
PHP |
Charles Fol (@cfreal_) |
Bug Bounty | 2022-06-25 | 2023-06-13 |
1430 | Bug: Cisco IOS SNMPv3 ACL Issues |
Information disclosure |
Cisco |
Gerry Gosselin (@ggPixelHealth) |
Bug Bounty | 2022-06-26 | 2023-06-13 |
1429 | Hyperlink Injection On IRC Cloud |
Hyperlink injection |
IRCCloud |
Aswin K V (@deep_marketer_) |
Bug Bounty | 2022-06-26 | 2023-06-13 |
1428 | Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135) |
SSRF |
Atlassian |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-06-26 | 2023-06-13 |
1427 | CVE-2022-32205: Set-Cookie denial of service |
DoS |
Internet Bug Bounty (curl) |
Harry Sintonen |
Bug Bounty | 2022-06-27 | 2023-06-13 |
1426 | CVE-2022-32206: HTTP compression denial of service |
DoS |
Internet Bug Bounty (curl) |
Harry Sintonen |
Bug Bounty | 2022-06-27 | 2023-06-13 |
1425 | CVE-2022-32207: Unpreserved file permissions |
Improper Preservation of Permissions |
Internet Bug Bounty (curl) |
Harry Sintonen |
Bug Bounty | 2022-06-27 | 2023-06-13 |
1424 | CVE-2022-32208: FTP-KRB bad message verification |
MiTM |
Internet Bug Bounty (curl) |
Harry Sintonen |
Bug Bounty | 2022-06-27 | 2023-06-13 |
1423 | HTML and Hyperlink Injection via Share Option In Microsoft Onenote Application |
HTML injection
Phishing |
Microsoft |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1422 | CVE-2022-30522 – Denial of Service (DoS) Vulnerability in Apache httpd “mod_sed” filter |
DoS |
Internet Bug Bounty |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1421 | CVE-2021-3779: Ruby-MySQL Gem Client File Read (FIXED) |
Client File Read |
Rapid7 |
Hans-Martin Münch (@h0ng10) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1420 | Access control worth $2000 (everyone missed this IDOR+Access control between two admins.) |
IDOR
Broken Access Control |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1419 | FabricScape: Escaping Service Fabric and Taking Over the Cluster |
Container escape
Local Privilege Escalation
Cross-tenant vulnerability |
Microsoft |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1418 | Bypassing .NET Serialization Binders |
Insecure deserialization
RCE |
Microsoft |
Markus Wulftange (@mwulftange) |
Bug Bounty | 2022-06-28 | 2023-06-13 |