954 | Google SSO misconfiguration leading to Account Takeover |
Authentication bypass
Account takeover
SSO |
NA |
0x4KD (@0x4kd) |
Bug Bounty | 2022-10-14 | 2023-06-13 |
909 | Support supports a Hacker |
Social engineering
Spoofing
Authorization flaw
Account takeover |
NA |
mechboy (@mechboy_) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
906 | GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown |
OS command injection
Arbitrary file read
Information disclosure
Account takeover
Stored XSS
Lack of rate limiting
Weak credentials
Password policy bypass |
GL.iNet |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
851 | My First Account Takeover |
Account takeover
Logic flaw |
NA |
JAI NIRESH J |
Bug Bounty | 2022-11-09 | 2023-06-13 |
845 | How Sigstore quickly patched an upstream vulnerability |
OAuth
Account takeover
Phishing |
Sigstore
dex |
Joern Schneeweisz |
Bug Bounty | 2022-11-10 | 2023-06-13 |
819 | Account Takeover Worth of $2500 |
Account takeover
IDOR |
NA |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2022-11-16 | 2023-06-13 |
809 | SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover |
Account takeover
Azure AD
Cloud |
Microsoft |
Tomer Nahum (@TomerNahum1) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
807 | From Static domain to Account Takeover |
Account takeover
Logic flaw |
NA |
Demon (@R29k_) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
800 | My Account Takeover Writeup: $5000 |
Lack of rate limiting
Bruteforce |
NA |
MRD7 (@_mrd7_) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
787 | Account Takeover in KAYAK |
Account takeover
Android
Insecure deeplink |
KAYAK |
Carlos Bello |
Bug Bounty | 2022-11-23 | 2023-06-13 |
775 | How I hacked into a government e-learning website |
IDOR
Account takeover |
NA |
iamgk808 (@iamgk808) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
773 | WebView XSS, account takeover |
Webview XSS
Android
Account takeover
Improper Export of Android Application Components |
NA |
shafou |
Bug Bounty | 2022-11-26 | 2023-06-13 |
768 | Access Any Owner Account without Authentication (Auth bypass + 2FA bypass) |
Authentication bypass
MFA bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
765 | 2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation |
Authentication bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
735 | Account Takeover - Inside The Tenant |
Account takeover
Information disclosure |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-12-03 | 2023-06-13 |
728 | OTP Leaking Through Cookie Leads to Account Takeover |
Information disclosure
Account takeover |
NA |
ag3n7 |
Bug Bounty | 2022-12-05 | 2023-06-13 |
666 | Zero Click To Account Takeover (IDOR + XSS) |
IDOR
XSS
Account takeover |
NA |
Arman (@M7arm4n) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
638 | Account Takeover Due to Cognito Misconfiguration Earns Me €xxxx |
Amazon cognito misconfiguration
Account takeover |
NA |
Mukund Bhuva (@MukundBhuva) |
Bug Bounty | 2022-12-29 | 2023-06-13 |
637 | How I got a Bug At Apple that lead’s to takeover accounts of any user who view my profile |
XSS
Account takeover |
Apple |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-12-29 | 2023-06-13 |
633 | How I took over an admin panel and got $500 |
Blind XSS
Account takeover |
NA |
Muhammed Mubarak |
Bug Bounty | 2023-01-01 | 2023-06-13 |
629 | An amazing way to turn a xss into an ATO |
XSS
Account takeover |
NA |
Naka |
Bug Bounty | 2023-01-02 | 2023-06-13 |
621 | Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More |
Account takeover
SSO
RCE
Authorization bypass
SQL injection
Mass assignment
Information disclosure |
Kia
Honda
Infiniti
Nissan
Acura
Mercedes-Benz
Hyundai
Genesis
BMW
Rolls Royce
Ferrari
Spireon
Ford
Reviver
Porsche
Toyota
Jaguar
Land Rover
SiriusXM |
Sam Curry (@samwcyo) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
602 | Full Team Takeover |
Account takeover
Broken Access Control |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
601 | How I Earned $1000 From Business Logic Vulnerability (account takeover) |
Logic flaw
Account takeover |
NA |
andika |
Bug Bounty | 2023-01-10 | 2023-06-13 |