1840 | SQL Injection, Reflected XSS and Information Disclosure in one subdomain in just 10 minutes |
SQL injection
XSS
Information disclosure |
NA |
Mahmoud Hamed (@7odamo_) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1835 | Story of critical security flaws I found in Glints |
IDOR
Information disclosure |
Glints |
huli (@aszx87410) |
Bug Bounty | 2022-02-09 | 2023-06-13 |
1814 | Hacked Dutch Government Website. All I got was this l̶o̶u̶s̶y̶ cool T-Shirt. |
Information disclosure |
Dutch Government |
Romesh chander |
Bug Bounty | 2022-02-16 | 2023-06-13 |
1803 | How I get my first SWAG from SIDN (Sensitive Data Exposer) |
Directory listing
Information disclosure
403 bypass |
SIDN |
remonsec (@remonsec) |
Bug Bounty | 2022-02-19 | 2023-06-13 |
1773 | Skype extension: All functionality broken? Still exploitable! |
Information disclosure
Privacy issue |
Microsoft |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1772 | [ Directory Traversal attack ] How did I find it using GitHub |
Information disclosure
Path traversal |
NA |
Fenrir (@leetibrahim) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1762 | Some critical vulnerabilities found with passive analysis on bug bounty programs explained |
Information disclosure
Logic flaw |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2022-03-07 | 2023-06-13 |
1745 | I have Found Microsoft Subdomain Website database list, database username, password |
Information disclosure |
Microsoft |
Bot Ami (@Botami143) |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1726 | SSD Advisory – Exchange Server GetWacInfo Information Disclosure Vulnerability |
XXE
Information disclosure |
Microsoft |
Alex Birnberg (@alexbirnberg) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1712 | Bug Bounty catches part -1 |
Authentication bypass
Information disclosure
Broken Access Control |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-20 | 2023-06-13 |
1707 | Google Maps API Key Unauthorized Use Case |
Information disclosure |
NA |
Dan Barros |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1706 | Story about more than 3.5 million PII leakage in Yahoo!!! |
IDOR
Information disclosure
iOS |
Yahoo! / Verizon Media |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1704 | Authentication bypass using root array |
Authentication bypass
Information disclosure |
NA |
Eslam Akl (@eslam3kll) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1685 | CVE-2022-22948: Sensitive Information Disclosure in VMware vCenter |
Information disclosure |
VMware |
Yuval Lazar |
Bug Bounty | 2022-03-29 | 2023-06-13 |
1658 | Azure Active Directory Exposes Internal Information |
Information disclosure |
Microsoft |
Secureworks Counter Threat Unit (@Secureworks) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1656 | New npm Flaws Let Attackers Better Target Packages for Account Takeover |
Information disclosure |
GitHub |
Yakir Kadkoda |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1653 | Azure Active Directory Exposes Internal Information |
Cloud
Information disclosure
Azure AD |
Microsoft (Azure) |
Counter Threat Unit Research Team |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1650 | How i got access to 1600k Users PII Data $$$$ |
Information disclosure |
NA |
Gokul AP (@CodingGokul) |
Bug Bounty | 2022-04-06 | 2023-06-13 |
1638 | NotGitBleed |
Information disclosure |
GitHub |
Aaron Devaney |
Bug Bounty | 2022-04-11 | 2023-06-13 |
1628 | MY First Bug In Hackerone |
Information disclosure |
NA |
anjaneyulu kanakatla |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1624 | United Nations bug bounty[writeup] |
Information disclosure |
United Nations |
Debprasad Banerjee |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1616 | XSLeaking with my best bud SOP |
Information disclosure |
Microsoft |
Ha Anh Hoang |
Bug Bounty | 2022-04-15 | 2023-06-13 |
1607 | Gaining Unlimited access to graph AuditLogs endpoint using complex filters with non-privileged user account |
Information disclosure
Privilege escalation |
Microsoft |
Joosua Santasalo (@SantasaloJoosua) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1603 | Adventures Into The MeowCorp Bug Bounty Program |
Information disclosure
Weak credentials
SSRF
.git folder disclosure
RCE |
NA |
Nirmal Thapa (@tnirmalz) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1598 | Fuzzing and credentials leakage..awesome bug hunting writeup |
Hardcoded credentials
Information disclosure |
NA |
Abdalrahman Alshammas |
Bug Bounty | 2022-04-25 | 2023-06-13 |