1080 | Security Advisory: NETGEAR Routers FunJSQ Vulnerabilities |
OS command injection
RCE
MiTM |
Netgear |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1079 | Breaking Bitbucket: Pre Auth Remote Command Execution (CVE-2022-36804) |
RCE
OS command injection |
Atlassian |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1078 | HTTP Desync Attack (Request Smuggling) - Mass Account Takeover at a Cryptocurrency based asset and 121 other websites |
HTTP Request Smuggling
Desync attack |
NA |
Ankit Singh (@AnkitCuriosity) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1076 | Abusing Broken Link In Fitbit (Google Acquisition)To Collect BugBounty Reports On Behalf Of Google ! |
Broken link hijacking |
Google |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2022-09-16 | 2023-06-13 |
1075 | Getting Paid With Just Picking Color — Bug Bounty |
CSS injection |
NA |
Redza |
Bug Bounty | 2022-09-16 | 2023-06-13 |
1074 | Cloning internal Google repos for fun and… info? |
Authorization flaw |
Google |
Luke Berner |
Bug Bounty | 2022-09-16 | 2023-06-13 |
1073 | How i made the multiple hall of fame in Nokia within 2 minutes |
Clickjacking |
Nokia |
Vedavyasan |
Bug Bounty | 2022-09-17 | 2023-06-13 |
1072 | How an Akamai misconfiguration earned us USD 46.000 |
HTTP request smuggling |
Akamai
Microsoft
Apple |
Francesco Mariani (@_medusa_1_) |
Bug Bounty | 2022-09-17 | 2023-06-13 |
1071 | How i Found Unauthorized Bypass RCE |
RCE
Old components with known vulnerabilities |
NA |
Yashshirke |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1070 | SSRF Attack Leading To AWS Metadata |
SSRF |
CERT-EU |
ParagBagul |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1069 | Bug Bounty { How I found an Sensitive Information Disclosure( Reconnaissance ) } |
Information disclosure |
NA |
S Rahul (@7srambo) |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1068 | Turning Your Computer Into a GPS Tracker With Apple Maps |
Privacy issue
Information disclosure |
Apple |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1067 | Android Application Forgot Password Token Leakage Leading to Account Takeover |
Information disclosure
Password reset
Account takeover
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-19 | 2023-06-13 |
1066 | How to hack Github Actions |
CI/CD |
GitHub |
StackOverflowExcept1on |
Bug Bounty | 2022-09-19 | 2023-06-13 |
1065 | SSD Advisory – Linux CLOCK_THREAD_CPUTIME_ID LPE |
Memory corruption
Race condition
Kernel hacking |
Linux Kernel Organization |
- |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1064 | Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286) |
Local Privilege Escalation
Windows
Driver hacking |
Seagate |
x86matthew (@x86matthew) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1063 | Privilege Escalation Leads to making authenticated actions (payment processing, creating invoices.. etc) |
Privilege escalation
Authorization flaw |
NA |
X-Vector (@XVector11) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1062 | Tag Myself in Your Favorite TikTok Artist Video [IDOR] |
IDOR |
TikTok |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1061 | 7,500$ – IDOR on Apple [consultants.apple.com] |
IDOR |
Apple |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1060 | AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes |
Cloud
Cross-tenant vulnerability
Authorization flaw |
Oracle |
Elad Gabay (@eladgabay_) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1059 | Apollo Router Security Audit Report (Q2 2022) |
DoS
CSRF |
Apollo GraphQL |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1058 | Securing Developer Tools: OneDev Remote Code Execution |
RCE
SSRF
Broken Access Control
Container escape |
OneDev |
Paul Gerste |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1057 | How we Abused Repository Webhooks to Access Internal CI Systems at Scale |
CI/CD |
NA |
Omer Gil (@omer_gil) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1056 | Parameters in Lambda Functions that lead to XSS and Injection |
XSS
Serverless |
AWS |
Teri Radichel (@TeriRadichel) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1055 | Mass Assignment Leading to Pre Account Takeover |
Mass assignment |
NA |
Cyberali |
Bug Bounty | 2022-09-21 | 2023-06-13 |