2071 | Keybase App Vulnerability: Incomplete Cleanup of Messages In Keybase for Android/iOS, CVE-2021-34421 |
Information disclosure |
Keybase |
Olivia O’Hara (@oliviaohara) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2068 | CVE-2021-42306 CredManifest: App Registration Certificates Stored in Azure Active Directory |
Information disclosure |
Microsoft |
Karl Fosaaen (@kfosaaen) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2064 | How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud |
Information disclosure
Authentication flaw |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
2051 | Unauthenticated Sensitive Information Disclosure at [REDACTED] |
Old components with known vulnerabilities
Information disclosure |
NA |
Rizaldi Wahaz (@wah_haz) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2046 | How I got my first bounty on financial sector gateway site by using Previous GraphQL vulnerabilities. |
Information disclosure
GraphQL |
NA |
Night Hawk |
Bug Bounty | 2021-11-26 | 2023-06-13 |
2028 | Disclose Ad Accounts linked with Instagram Accounts |
Information disclosure
Logic flaw
GraphQL |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2015 | Microsoft Vancouver leaking website credentials via overlooked DS_STORE file |
Information disclosure |
Microsoft |
CyberNews Team |
Bug Bounty | 2021-12-08 | 2023-06-13 |
2010 | Exploiting S3 bucket with path folder to Access PII info of A BANK |
AWS misconfiguration
Information disclosure |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
1977 | MS Teams: 1 feature, 4 vulnerabilities |
SSRF
Information disclosure
DoS
Spoofing |
Microsoft |
Fabian Bräunlein |
Bug Bounty | 2021-12-22 | 2023-06-13 |
1974 | Information Disclosure leads to sensitive credential($$$) |
Information disclosure |
NA |
khan mamun (@mamunwhh) |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1957 | Here’s How I Could Read Anyone’s Apple ID Metrics Remotely. |
Information disclosure |
Apple |
Faizan Ahmad Wani |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1934 | A Tale Of 5250$: How I Accessed Millions Of User’s Data Including Their National ID’s |
AWS misconfiguration
Information disclosure |
NA |
Sam (@__Sam0_0) |
Bug Bounty | 2022-01-07 | 2023-06-13 |
1917 | 120 Days of High Frequency Hunting |
SSRF
LFI
Information disclosure
Broken Access Control
Authentication bypass
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-15 | 2023-06-13 |
1903 | Hashing the Favicon.ico |
Information disclosure |
NA |
Ski Mask (@Ski_Mask0) |
Bug Bounty | 2022-01-21 | 2023-06-13 |
1901 | 120 Days of Frequent Hacking |
SSRF
LFI
Information disclosure
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-21 | 2023-06-13 |
1900 | How I was able to find multiple vulnerabilities of a Symfony Web Framework web application |
Debug mode enabled
Information disclosure |
NA |
Abid Ahmad (@RootIntrud3r) |
Bug Bounty | 2022-01-23 | 2023-06-13 |
1898 | Solarwinds Web Help Desk: When the Helpdesk is too Helpful |
Information disclosure
Hardcoded credentials |
SolarWinds |
Assetnote Security Research Team (@assetnote) |
Bug Bounty | 2022-01-23 | 2023-06-13 |
1891 | How I could have read your confidential bug reports by simple mail? |
Information disclosure
Logic flaw |
Microsoft |
Sudhakar Muthumani (@Sudhakarmuthu04) |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1867 | A story of leaking uninitialized memory from Fastly |
HTTP/3
Memory leak
Information disclosure |
Fastly |
Emil Lerner (@emil_lerner) |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1861 | A misconfigured Apache Airflow to AWS Account Compromise |
Outdated component with a known vulnerability
Privilege escalation
Information disclosure |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1858 | How I Tracked You Around The Globe 🌎 |
Information disclosure
Privacy issue |
Google (Waze) |
0xdroopy (@NikhilK50866227) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1853 | Write Up – Private Bug Bounty: RCE In EC2 Instance Via SSH With Private Key Exposed On Public Github Repository – $xx,000 USD |
Information disclosure |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1846 | Auth Bypass in Google Assistant |
Information disclosure
Authentication bypass |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-02-06 | 2023-06-13 |
1843 | What I Found on Sony Vulnerability Disclosure Program |
Information disclosure
Lack of rate limiting
Open redirect
IDOR
XSS |
Sony |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-02-07 | 2023-06-13 |