1054 | TypeORM Prototype Pollution Leading To SQL Injection (CVE-2022-36531) |
DoS
SQL injection |
TypeORM |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1053 | Tarfile: Exploiting the World With a 15-Year-Old Vulnerability |
Path traversal |
Python |
Kasimir Schulz (@Abraxus7331) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1052 | Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library |
Universal XSS
SSRF
Open redirect
Web cache poisoning |
Netlify
Gemini
PancakeSwap
Docusign
Moonpay
Celo |
Sam Curry (@samwcyo) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1051 | One takeover to rule them all |
Subdomain takeover |
EDF |
Gwendal Le Coguic (@gwendallecoguic) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1050 | Tarfile: Exploiting the World With a 15-Year-Old Vulnerability |
Path traversal |
Python |
Kasimir Schulz (@Abraxus7331) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1049 | How I Found Multiple SQL Injections in 5 Minutes in Bug Bounty |
SQL injection |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-09-22 | 2023-06-13 |
1048 | Making HTTP header injection critical via response queue poisoning |
HTTP header injection
HTTP request smuggling |
NA |
James Kettle (@albinowax) |
Bug Bounty | 2022-09-22 | 2023-06-13 |
1047 | Skype for Business Audit Part 1 - SKYPErsistence |
Local Privilege Escalation
Windows
Security code review |
Microsoft |
Florian Hauser (@frycos) |
Bug Bounty | 2022-09-22 | 2023-06-13 |
1046 | Exploiting Distroless Images |
Command injection
Arbitrary file read
Arbitrary file write
Container escape |
Google |
Daniel Teixeira (@TheRedOperator) |
Bug Bounty | 2022-09-22 | 2023-06-13 |
1045 | My First XSS |
Open redirect
XSS |
NA |
Avyukt Syrine (@AvyuktSyrine) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1044 | My First Valid Bug “Bypass the Admin Panel” |
Authentication bypass |
NA |
Digant Prajapati |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1043 | Arbitrary File Corruption: End - to - End Encrypted Messaging Application |
Insecure intent
Android |
NA |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1042 | WAF bypasses via 0days |
WAF bypass
Content-type confusion
Charset confusion |
ModSecurity |
Terjanq (@terjanq) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1041 | Pre-Auth Remote Code Execution - Web Page Test |
RCE
SSRF |
CatchPoint |
Laluka (@TheLaluka) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1040 | CVE-2022-35256 - HTTP Request Smuggling in NodeJS |
HTTP request smuggling |
Node.js |
VVX7 (@VV_X_7) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1039 | Complete take-over of Cisco Unified Communications Manager due consecutively misconfigurations |
Security misconfiguration
VoIP hacking |
NA |
hackthebox |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1038 | Microsoft Windows Shift F10 Bypass and Autopilot privilge escalation |
Local privilege escalation |
Microsoft |
Matek Kamilló (@k4m1ll0) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1037 | Blind XSS on Admin Portal Leads to Information Disclosure |
Blind XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1036 | Escalating SSTI to Reflected XSS using curly braces {} |
SSTI
XSS |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1035 | Stored XSS in Nvidia via Angular JS template injection |
CSTI
Stored XSS |
Nvidia |
Mohamed Abdelhady |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1034 | Shopping App Deeplink Arbitrary URLs |
Insecure deeplink
Android |
NA |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1033 | Tesla paid me $10,000 because of Directory Indexing |
Directory listing |
Tesla |
infiltrateops |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1032 | Blind account takeover |
Account takeover |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1031 | New Attack Paths? AS Requested Service Tickets |
Local Privilege Escalation
Windows
Kerberos
Active Directory |
Microsoft |
Charlie Clark (@exploitph) |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1030 | Skype for Business Audit Part 2 - SKYPErimeterleak |
SSRF
Security code review |
Microsoft |
Florian Hauser (@frycos) |
Bug Bounty | 2022-09-26 | 2023-06-13 |