1210 | RCE on Spip and Root-Me, v2! |
RCE
SSTI
DNS rebinding
XSS
Code injection
Unrestricted file upload |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1209 | Critical Local File Read in Electron Desktop App |
LFI |
Asana |
Renwa (@RenwaX23) |
Bug Bounty | 2022-08-17 | 2023-06-13 |
1208 | N/a to $750 bounty for a Blind XSS. |
Blind XSS |
NA |
Dirtycoder (@dirtycoder0124) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1207 | You Have One New Appwntment: Exploiting iCalendar Properties in Enterprise Applications |
XSS
SMTP injection |
VMware
Synology
Apple
Microsoft
Google
NextCloud |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1206 | Let%27s Dance in the Cache - Destabilizing Hash Table on Microsoft IIS! |
DoS
Web cache poisoning
Authentication bypass |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1205 | Fishbowl Disclosure: CVE-2022-29805 |
Insecure deserialization |
Fishbowl |
Michael Rand |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1204 | Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets? |
Robotic Process Automation
Insecure deserialization
SQL injection
MiTM |
Blue Prism |
Nimrod Stoler (@n1mr0d5) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1203 | Outlook CVE-2022-35742 |
DoS |
Microsoft |
insu (@hpy_insu) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1201 | Amazon Quickly Fixed A Vulnerability In Ring Android App That Could Expose Users’ Camera Recordings |
XSS
iOS
Android |
Amazon |
David Sopas (@dsopas) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1200 | Uncovering a ChromeOS remote memory corruption vulnerability |
Memory corruption |
Google |
Microsoft 365 Defender Research Team |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1199 | Account takeover worth $1000 |
Account takeover
Authentication bypass
Information disclosure
Password reset |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1198 | Never underestimate the power of open redirect, a story of a full account takeover |
Open redirect
Account takeover
Token leak |
NA |
Ibrahim Auwal (@ibrahimatix0x01) |
Bug Bounty | 2022-08-20 | 2023-06-13 |
1197 | VPNs on iOS are a scam |
Privacy issue |
Apple |
Michael Horowitz (@defensivecomput) |
Bug Bounty | 2022-08-20 | 2023-06-13 |
1196 | Failed Coding Assessment to Remote Code Execution - Part 1 |
RCE |
HackerEarth |
Akash Chhabra (@_hackingguy) |
Bug Bounty | 2022-08-20 | 2023-06-13 |
1195 | Blind command injection |
RCE
OS command injection |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-21 | 2023-06-13 |
1194 | Blockchain Network is Secured! But not the apps and their Integrations |
Payment tampering
Logic flaw |
NA |
Keyur Talati |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1193 | How a Port scan got me Nokia Hall of Fame |
Missing authentication
Information disclosure |
Nokia |
Mani Sashank |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1192 | SSRF & Google HOF(Hall of Fame) |
SSRF |
Google |
Aman Pareek (@aman_notsogreat) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1191 | Useless path traversals in Zyxel admin interface (CVE-2022-2030) |
Path traversal |
Zyxel |
Maurizio Agazzini (@0x696e6f6465) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1190 | Vulnerability in Linux containers – investigation and mitigation |
Local Privilege Escalation |
Moby Project |
Steven Murdoch (@sjmurdoch) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1189 | Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager |
Hardcoded credentials
Information disclosure |
SAP |
Arpine Maghakyan |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1188 | Paracosme - CVE-2022-33318 - Remote Code Execution in ICONICS Genesis64 |
Memory corruption
RCE |
ICONICS |
Axel Souchet (@0vercl0k) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1187 | Break Me Out Of Sandbox In Old Pipe - CVE-2022-22715 Windows Dirty Pipe |
Local Privilege Escalation |
Microsoft |
k0shl (@KeyZ3r0) |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1186 | But You Told Me You Were Safe: Attacking The Mozilla Firefox Renderer (Part 1) |
Browser hacking
RCE
Prototype pollution |
Mozilla |
Hossein Lotfi (@hosselot) |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1185 | [CVE-2020-2733] JD Edwards EnterpriseOne Tools admin password not adequately protected |
Information disclosure |
Oracle |
Vahagn Vardanyan (@vah_13) |
Bug Bounty | 2022-08-23 | 2023-06-13 |