1365 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
RCE
Arbitrary Object Instantiation
Bruteforce
LDAP injection |
NA |
Arseniy Sharoglazov (@_mohemiv) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1364 | How I spammed a Google meet (But for good) |
DoS |
Google |
Shaunak (SHA25) |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1362 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
Lack of rate limiting
Privilege escalation
IDOR
Account takeover |
NA |
Muhammad Talha / evilmango |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1361 | Good Recon Leads To Senssitive Accounts |
Information disclosure
Username enumeration |
NA |
Milanjain |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1360 | Ability to login as google staff in Google Cloud Community |
Privilege escalation |
Google |
Gaurav Bhatia |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1359 | Authorization token leak from verify email endpoint |
Account takeover
Information disclosure |
NA |
Vengeance |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1358 | First Bug Bounty from DOS: Taking the service down |
DoS |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1357 | Business logic error |
Logic flaw |
NA |
anjaneyulu kanakatla |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1356 | Subdomain takeover and Text injection on a 404 error page-$100 bounty |
Subdomain takeover |
NA |
Jeewan Bhatta (@thenullkid) |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1355 | CRLF to Account takeover (chaining bugs) |
CRLF injection
XSS
Account takeover |
NA |
MoSec (@moe1n1) |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1354 | Going beyond Alert with XSS |
XSS
Account takeover |
NA |
pipsh |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1353 | A Story Of My First Bug Bounty |
Information disclosure |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2022-07-17 | 2023-06-13 |
1352 | FFUF-ing RECON, or how to get to P1–P3 from a slightly different recon |
vHost misconfiguration
403 bypass
Information disclosure |
NA |
Vuk Ivanovic |
Bug Bounty | 2022-07-17 | 2023-06-13 |
1351 | CVE-2022–35909 / CVE-2022–35910, Incorrect Access Control and XSS Stored to Jellyfin |
Broken Access Control
XSS |
jellyfin |
Dan Barros |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1350 | Good things takes time | Story of my first “valid” critical bug! |
Missing authentication
Exposed administrative interface |
NA |
Kr1shna 4garwal (@Kr1shna4garwal) |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1349 | Hey Google Lets submit bug from Victim Account ! |
IDOR |
Google |
Prasanth Elangovan |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1348 | Hacking Facebook Invoice: How I could’ve bought anything for Free from Facebook Business Pages |
Payment bypass |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1347 | MyBB 0day Authenticated Remote code execution |
RCE
Argument injection |
MyBB |
Anna / 416e6e61 (@AnnaViolet20) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1346 | Authomize Discovers PassBleed Password Stealing and Impersonation Risks in Okta |
Sensitive data sent over an unencrypted channel
Authorization flaw
Information disclosure |
Okta |
Authomize (@Authomize) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1345 | Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass |
Local Privilege Escalation |
OPC Foundation |
Sector 7 (@sector7_nl) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1344 | How i was able to bypass Open Redirect 3 times on same program. |
Open redirect |
NA |
himanshu pdy (@himanshu_pdy) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1343 | Logging Passwords in Plaintext in Azure Arc |
Information disclosure
Local Privilege Escalation
Cloud |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1342 | SSD Advisory – Microsoft SharePoint Server WizardConnectToDataStep4 Deserialization Of Untrusted Data RCE |
Insecure deserialization
RCE |
Microsoft |
Alex Birnberg (@alexbirnberg) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1341 | CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation |
Local Privilege Escalation |
Zyxel |
Jake Baines (@Junior_Baines) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1340 | Local File Inclusion (interesting method) |
LFI |
NA |
Captain hook |
Bug Bounty | 2022-07-19 | 2023-06-13 |