2119 | Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD |
Broken authentication
Authentication flaw |
GoCD |
Sonar (@SonarSource) |
Bug Bounty | 2021-10-27 | 2023-06-13 |
2110 | How I found Command Injection via Obsolete PHPThumb |
OS command injection
RCE |
NA |
Sushant Kamble |
Bug Bounty | 2021-10-30 | 2023-06-13 |
2106 | Sitecore Experience Platform Pre-Auth RCE - CVE-2021-42237 |
RCE
Insecure deserialization
Security code review |
Sitecore |
Shubham Shah (@infosec_au) |
Bug Bounty | 2021-11-01 | 2023-06-13 |
2105 | A Technical Analysis of CVE-2021-30864: Bypassing App Sandbox Restrictions |
Local Privilege Escalation
MacOS |
Apple |
Perception Point (@PerceptionPo1nt) |
Bug Bounty | 2021-11-03 | 2023-06-13 |
2102 | Multiple Concrete CMS Vulnerabilities ( Part1 – RCE ) |
RCE
Race condition |
Concrete CMS |
FORTBRIDGE (@FORTBRIDGE1) |
Bug Bounty | 2021-11-05 | 2023-06-13 |
2089 | Unrestricted File Upload Leads to SSRF and RCE |
ImageTragick
Unrestricted file upload
SSRF
RCE |
NA |
Muhammad Adel (@ItsFadinG_) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2073 | Diving into Open-source LMS Codebases |
Insecure file upload
Insecure deserialization
RCE
CSRF
SQL injection
Reflected XSS |
Moodle
Chamilo LMS |
Poh Jia Hao (@Chocologicall) |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2065 | A Story of an Epic Blind Remote Code Execution(RCE) |
RCE
OS command injection |
NA |
Akash Solanki (@MAALP1225) |
Bug Bounty | 2021-11-18 | 2023-06-13 |
2059 | [BugBounty] XSS with Markdown — Exploit & Fix on OpenSource |
XSS |
NA |
Lê Thành Phúc |
Bug Bounty | 2021-11-22 | 2023-06-13 |
2041 | This Microsoft Windows RCE Vulnerability Gives an Attacker Complete Control |
Memory corruption |
Microsoft |
Malcolm Stagg (@malcolmst) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2040 | NodeBB 1.18.4 - Remote Code Execution With One Shot |
RCE
XSS
Authentication bypass
Arbitrary file read |
NodeBB |
Sonar (@SonarSource) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2030 | AWS SageMaker Jupyter Notebook Instance Takeover |
Self-XSS
CSRF
RCE |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2024 | How I managed to hack User accounts of a billion-dollar sport platform |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2021-12-04 | 2023-06-13 |
2019 | Hacking into Admin Panel of U.S Federal government system C.A.R.S — without credentials. |
Client-side enforcement of server-side security
Privilege escalation |
U.S. General Services Administration |
Hazem Brini (@ImJungsuu) |
Bug Bounty | 2021-12-07 | 2023-06-13 |
2017 | Windows 10 RCE: The exploit is in the link |
RCE |
Microsoft |
Fabian Bräunlein |
Bug Bounty | 2021-12-07 | 2023-06-13 |
2009 | File Upload to RCE |
Unrestricted file upload |
NA |
Ahmed Magdy (@8Ahmed88Magdy8) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
2008 | A phishing document signed by Microsoft – part 1 |
Phishing
RCE |
Microsoft |
Pieter Ceelen (@ptrpieter) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
1992 | Exploitation Of CVE-2021-21220 – From Incorrect JIT Behavior To RCE |
Browser hacking
Memory corruption
RCE |
Google
Microsoft |
Bruno Keith (@bkth_) |
Bug Bounty | 2021-12-16 | 2023-06-13 |
1986 | RCE in Visual Studio Code%27s Remote WSL for Fun and Negative Profit |
RCE |
Microsoft |
Parsia Hackerman (@cryptogangsta) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1983 | How I earned $$$ by bypassing 2FA |
MFA bypass
Forced browsing |
NA |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1982 | SSD Advisory – Rocket.Chat Client-side Remote Code Execution |
RCE
MacOS |
Rocket.Chat |
- |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1980 | NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories |
Security misconfiguration
.git folder disclosure |
Microsoft |
Wiz (@wiz_io) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1968 | Bi/ug Bounties and HyperV RCE Research |
RCE |
Microsoft Hyper-V |
Peter Hlavaty (@rezer0dai) |
Bug Bounty | 2021-12-27 | 2023-06-13 |
1966 | Bounty Evaluation GitHub = $15,000 US Dollars | Rate Limit |
Bruteforce
Email verification bypass
Account takeover |
GitHub |
Taniya Agarwal |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1964 | Remote Code Execution in Google Cloud Dataflow |
RCE |
Google |
Mike Brancato (@meatballninja) |
Bug Bounty | 2021-12-28 | 2023-06-13 |