1391 | PII Disclosure of Apple Users ($10k) |
IDOR
Lack of rate limiting
Bruteforce
Information disclosure |
Apple |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1390 | Account Takeover via Response Manipulation |
Authentication bypass
Account takeover
MFA bypass
HTTP response manipulation |
NA |
BUG HUNTER |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1389 | stored XSS and stored HTML Injection in United Nations Website |
XSS
HTML injection |
United Nations |
Ahmed Hassan |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1388 | Advisory | GLPI Service Management Software Multiple Vulnerabilities and Remote Code Execution |
SQL injection
RCE
LFI |
GLPI |
Nuri Çilengir (@ncilengir) |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1387 | Flash XSS in ajax.googleapis.com |
XSS |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1386 | An interesting idor that allowed me to See all projects ($$$$ Bounty) |
IDOR |
NA |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1385 | Exploiting SQL Injection at Authorization token |
SQL injection
Account takeover |
NA |
Basudev |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1384 | How I earned 200$ in Bug Bounty Program |
Information disclosure |
NA |
Idan Malihi |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1383 | Exploiting Authentication in AWS IAM Authenticator for Kubernetes |
Authentication flaw
Privilege escalation |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2022-07-11 | 2023-06-13 |
1381 | How we have pwned Root-Me in 2022 |
XSS
CSRF
RCE |
SPIP |
SpawnZii (@SpawnZii) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1380 | Remote Code Execution via Prototype Pollution in Blitz.js |
Prototype pollution
RCE |
Blitz.js |
Paul Gerste |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1379 | How a Simple IDOR Led Me to Delete Any Account |
IDOR
CSRF |
NA |
rajesh.r (@_rajesh_ranjan_) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1378 | Write Up 1: Hellosign Integration [Full Read SSRF] |
SSRF |
NA |
Soufiane Habti (@wld_basha) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1377 | Microsoft Azure Site Recovery DLL Hijacking |
DLL Hijacking
Privilege escalation |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1376 | CVE-2022-32223 Discovery: DLL Hijacking via npm CLI |
DLL Hijacking
Privilege escalation |
Node.js |
Yakir Kadkoda |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1375 | Leveraging the SQL Injection to Execute the XSS by Evading CSP |
CSP bypass
SQL injection
XSS |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1374 | Netwrix Auditor Advisory |
Insecure deserialization |
Netwrix |
Jordan Parkin |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1373 | CVE-2022-29885 - Don%27t Open That Port - A Denial Of Service vulnerability on Apache Tomcat Cluster Service Listener |
DoS |
Internet Bug Bounty |
void (@voidz0r) |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1372 | Hacking on a Private Program (Salseforce crm) |
RCE
OS command injection |
NA |
Maruf Hosan (@thinkermaruff) |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1371 | Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706 |
Local Privilege Escalation |
Apple |
Microsoft 365 Defender Research Team |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1370 | Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP |
XSS
CSP bypass
HTML injection |
Microsoft |
Numan Turle (@numanturle) |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1369 | From Open Redirect to Reflected XSS manually |
Open redirect
Reflected XSS |
NA |
Rodric |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1368 | CVE-2022-30136: Microsoft Windows Network File System V4 Remote Code Execution Vulnerability |
RCE
DoS
Memory corruption |
Microsoft |
Yuki Chen (@guhe120) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1367 | Abusing URL Shortners for fun and profit |
Information disclosure
Account takeover
IDOR |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1366 | Tableau Server Leaks Sensitive Information From Reflected XSS |
Reflected XSS |
Salesforce |
Simon Bouchard (@SimTwisted) |
Bug Bounty | 2022-07-14 | 2023-06-13 |