1314 | CVE-2022–36446 — Webmin 1.996 — Remote Code Execution (RCE — Authenticated) During Install New Packages |
RCE
OS command injection |
Webmin |
Emir Polat (@devilsgrins) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1313 | CVE-2022-26712: The POC for SIP-Bypass Is Even Tweetable |
MacOS
SIP bypass |
Apple |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1311 | Advisory | Roxy-WI Unauthenticated Remote Code Executions CVE-2022-31137 |
RCE
Authentication bypass |
Roxy-WI |
Nuri Çilengir (@ncilengir) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1310 | Hunting For Mass Assignment Vulnerabilities Using GitHub CodeSearch and grep.app |
Mass assignment |
freeCodeCamp |
Laurence Tennant |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1309 | Disclosing information with a side-channel in Django |
Side channel attack |
Django |
Dennis Brinkrolf (@DBrinkrolf) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1308 | CVE-2022-31813: Forwarding Addresses Is Hard |
Host header injection
DoS
IP address spoofing |
Internet Bug Bounty (Apache HTTPD) |
Gaetan Ferry (@_mabote_) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1307 | HTTP Parameter Pollution - It’s Contaminated Again |
HTTP parameter pollution
Rate limiting bypass |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1306 | Google XSS |
XSS |
Google |
NDevTK (@ndevtk) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1305 | Exploiting GitHub Actions on open source projects |
RCE |
Elastic |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1303 | SSD Advisory – Apple Safari IDN URL Spoofing |
URL spoofing |
Apple |
Dohyun Lee (@l33d0hyun) |
Bug Bounty | 2022-07-27 | 2023-06-13 |
1302 | Corrupting memory without memory corruption |
Memory corruption |
Google |
Man Yue Mo (@mmolgtm) |
Bug Bounty | 2022-07-27 | 2023-06-13 |
1301 | Vulnerability in Dahua’s ONVIF Implementation Threatens IP Camera Security |
MiTM |
Dahua |
Nozomi Networks Labs (@nozominetworks) |
Bug Bounty | 2022-07-28 | 2023-06-13 |
1300 | Researching Open Source apps for XSS to RCE flaws |
XSS
RCE |
NA |
Aleksey Solovev |
Bug Bounty | 2022-07-28 | 2023-06-13 |
1299 | “ParseThru” – Exploiting HTTP Parameter Smuggling in Golang |
HTTP Parameter Smuggling |
Harbor
Traefik
Skipper |
Daniel Abeles (@Daniel_Abeles) |
Bug Bounty | 2022-07-28 | 2023-06-13 |
1298 | Reading Message from Microsoft’s Private Yammer Group |
Authorization flaw |
Microsoft |
Meareg |
Bug Bounty | 2022-07-28 | 2023-06-13 |
1297 | Arris / Arris-variant DSL/Fiber router critical vulnerability exposure |
Path traversal
Memory corruption |
ARRIS |
Derek Abdine (@dabdine) |
Bug Bounty | 2022-07-29 | 2023-06-13 |
1296 | Business logic vulnerabilities |
Logic flaw
Payment tampering |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-07-29 | 2023-06-13 |
1295 | Discord Desktop - Remote Code Execution |
RCE
XSS
Sandbox bypass
CSP bypass |
Discord |
s1r1us (@s1r1u5_) |
Bug Bounty | 2022-07-29 | 2023-06-13 |
1293 | My Second CVE (CVE-2022-31855) |
OS command injection
Local Privilege Escalation |
RStudio |
y0ung_dst (@Y0ung_MA) |
Bug Bounty | 2022-07-30 | 2023-06-13 |
1292 | How I Earned €150 in 2 Minutes | HTML injection in email |
HTML injection |
NA |
Thillai Raj |
Bug Bounty | 2022-07-30 | 2023-06-13 |
1291 | How I get Full Account Takeover via stealing action’s login form | XSS |
XSS
Account takeover |
NA |
Mohamed Tarek (@timooon107) |
Bug Bounty | 2022-08-01 | 2023-06-13 |
1290 | Analysis of Adobe Acrobat Reader Javascript Doc.print() Use-After-Free Vulnerability (CVE-2022-34233) |
Memory corruption |
Adobe |
ThreatLabz (@Threatlabz) |
Bug Bounty | 2022-08-01 | 2023-06-13 |
1289 | How I earned $10,000 within the last 7 months — a 17y/o Edition |
Authorization flaw |
NA |
Gowtham Naidu Ponnana (@gowtham_ponnana) |
Bug Bounty | 2022-08-01 | 2023-06-13 |
1288 | Stored XSS to Account Takeover : Going beyond document.cookie | Stealing Session Data from IndexedDB |
Stored XSS
Account takeover |
NA |
Syed Mushfik Hasan Tahsin (@SMHTahsin33) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1287 | Instagram photo was present in data backup nearly after two years being deleted. |
Privacy issue |
Meta / Facebook |
Jeewan Bhatta (@thenullkid) |
Bug Bounty | 2022-08-02 | 2023-06-13 |