2261 | Your Vulnerability Is In Another OEM! |
Memory corruption
RCE |
Western Digital |
Lucas Georges |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2259 | RCE By Code Injection | Perl Reverse Shell |
RCE
Code injection |
NA |
Abdulrahman-Kamel |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2249 | Anti-crawler Burp Suite RCE |
RCE
Browser hacking |
PortSwigger |
Wfox |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2225 | 10 golden minutes for taking over a Chess.com account |
Lack of rate limiting
Bruteforce
Session expiration issue |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-09-14 | 2023-06-13 |
2224 | OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers |
Local Privilege Escalation
RCE |
Microsoft |
Nir Ohfeld (@nirohfeld) |
Bug Bounty | 2021-09-14 | 2023-06-13 |
2214 | All Your (d)Base Are Belong To Us, Part 1: Code Execution in Apache OpenOffice (CVE-2021–33035) |
RCE
Memory corruption |
Apache |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-09-17 | 2023-06-13 |
2212 | From phpinfo page to many P1 bugs and RCE. [Symfony] |
File disclosure
Information disclosure
RCE |
NA |
Abdelrahman Khaled |
Bug Bounty | 2021-09-18 | 2023-06-13 |
2207 | 5 RCEs in npm for $15,000 |
RCE |
NA |
Robert Chen (@NotDeGhost) |
Bug Bounty | 2021-09-20 | 2023-06-13 |
2206 | Mama Always Told Me Not to Trust Strangers without Certificates |
MiTM
RCE |
Netgear |
Adam (@AdamOfDc949) |
Bug Bounty | 2021-09-21 | 2023-06-13 |
2205 | RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through |
RCE
Path traversal |
Citrix Systems |
Markus Wulftange (@mwulftange) |
Bug Bounty | 2021-09-21 | 2023-06-13 |
2195 | $8,000 Bug Bounty Highlight: XSS to RCE in the Opera Browser |
XSS
RCE |
Opera |
Renwa (@RenwaX23) |
Bug Bounty | 2021-09-24 | 2023-06-13 |
2193 | Remote Command Execution in Visual Studio Code Remote Development Extension |
RCE |
Microsoft |
Abdel Adim `smaury` Oisfi (@smaury92) |
Bug Bounty | 2021-09-24 | 2023-06-13 |
2191 | Attack Surface Analysis - Part 3 - Resurrected Code Execution |
RCE |
NA |
Parsia Hackerman (@cryptogangsta) |
Bug Bounty | 2021-09-26 | 2023-06-13 |
2183 | Force Browsing bug at Facebook business plan ($500 Bounty) |
Authorization flaw
Forced browsing |
Meta / Facebook |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2021-09-29 | 2023-06-13 |
2170 | CVE-2021-26084 |
RCE |
Atlassian |
snowyyowl (@bennyyjacob) |
Bug Bounty | 2021-10-05 | 2023-06-13 |
2169 | How I got access to many PIIs through a source code leak |
Information disclosure |
NA |
Supras (@LdrTom) |
Bug Bounty | 2021-10-05 | 2023-06-13 |
2165 | CVE-2021-26420: Remote Code Execution In Sharepoint Via Workflow Compilation |
RCE |
Microsoft |
- |
Bug Bounty | 2021-10-06 | 2023-06-13 |
2146 | Remote code execution in Managed Anthos Service Mesh control plane |
RCE |
Google |
Anthony Weems |
Bug Bounty | 2021-10-15 | 2023-06-13 |
2145 | Exploitation of file’s download parameters to create potential risk of malware delivery: $200 bug! |
CSRF
RCE |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2143 | How I Escalated a Time-Based SQL Injection to RCE |
SQL injection
RCE |
Sony |
JM Sanchez / 0xEchidonut (@jmrcsnchz) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2142 | Independently Secure, Together Not So Much – A Story Of 2 WP Plugins |
RCE
Race condition
Unrestricted file upload
Security code review |
NA |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2140 | Shells And SOAP: Websphere Deserialization To RCE |
RCE
Insecure deserialization |
IBM |
Wyatt Dahlenburg (@wdahlenb) |
Bug Bounty | 2021-10-18 | 2023-06-13 |
2134 | All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646) |
RCE
Memory corruption |
Microsoft |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2129 | Discourse SNS webhook RCE |
RCE
Signature validation bypass |
Discourse |
joernchen (@joernchen) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2127 | How I was able to revoke your Instagram 2FA |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Dhiyaneshwaran (@DhiyaneshDK) |
Bug Bounty | 2021-10-23 | 2023-06-13 |