1003 | Bugcrowd — Tale of multiple misconfigurations!! ❌ |
Account takeover
OAuth
OTP bypass
Password reset |
NA |
Vaibhav Lakhani |
Bug Bounty | 2022-10-04 | 2023-06-13 |
1002 | Securing Developer Tools: A New Supply Chain Attack on PHP |
Argument injection
RCE
Supply chain attack
Security code review |
Packagist |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2022-10-04 | 2023-06-13 |
1001 | Hacking TMNF: Part 1 - Fuzzing the game server |
RCE
Memory corruption
Format string vulnerability |
Ubisoft |
- |
Bug Bounty | 2022-10-05 | 2023-06-13 |
1000 | How I Found A P1 Bug |
Authentication bypass
Information disclosure |
NA |
Amith |
Bug Bounty | 2022-10-05 | 2023-06-13 |
999 | Appsmith Patches Full-Read SSRF Vulnerabilities Reported by CloudSEK |
SSRF |
Appsmith |
Sparsh Kulshrestha (@d0tdotslash) |
Bug Bounty | 2022-10-05 | 2023-06-13 |
998 | Exploit Disclosure: Turning Thunderbird into a Decryption Oracle |
Privacy issue |
Mozilla (Thunderbird) |
Sarah Jamie Lewis (@SarahJamieLewis) |
Bug Bounty | 2022-10-05 | 2023-06-13 |
997 | A Deep Dive of CVE-2022–33987 (Got allows a redirect to a UNIX socket) |
SSRF |
MediaWiki |
Chaim Sanders |
Bug Bounty | 2022-10-06 | 2023-06-13 |
996 | Error based SQL Injection with WAF bypass manual Exploit 100% |
SQL injection
WAF bypass |
NA |
Ahmed Qaramany (@c0nqr0r) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
995 | Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style |
DNS cache poisoning
Kaminsky attack |
NA |
Timo Longin |
Bug Bounty | 2022-10-06 | 2023-06-13 |
994 | CVE-2022-41343 |
RCE
Insecure deserialization
Phar deserialization |
dompdf |
Tanto Security team (@TantoSecurity) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
993 | Mr. Robot: Self Xss from Informative to high 1200$ ,csrf, open redirect,self xss to stored |
Self-XSS
CSRF |
NA |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
992 | SSD Advisory – pfSense Post Auth RCE |
RCE
Privilege escalation |
pfSense |
이예랑 (@yelang123x) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
991 | Technical Advisory – OpenJDK – Weak Parsing Logic in java.net.InetAddress and Related Classes |
IP address validation bypass
Hostname validation bypass
URL parsing issue |
OpenJDK |
Jeff Dileo (@ChaosDatumz) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
990 | Full Company Building Takeover |
Information disclosure |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
989 | CVE-2022–36635 — A SQL Injection in ZKSecurityBio to RCE |
SQL injection |
ZKTeco |
Caio Burgardt (@CaioBurgardt) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
988 | Insecure Comments |
IDOR
Authorization flaw |
Microsoft |
Meareg |
Bug Bounty | 2022-10-07 | 2023-06-13 |
987 | Auth Bypass Via Exposed Credentials |
Hardcoded API keys |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-10-07 | 2023-06-13 |
986 | Vulnerabilities in Online Payment Systems |
Payment bypass
Payment tampering
Logic flaw |
NA |
Claudio Moran |
Bug Bounty | 2022-10-08 | 2023-06-13 |
985 | The easiest bug to get a Hall of fame from a Billion dollar company. |
GraphQL
Information disclosure |
GeHealthcare |
Ravaan |
Bug Bounty | 2022-10-10 | 2023-06-13 |
984 | Persistent PHP Payloads In PNGs: How To Inject PHP Code In An Image – And Keep It There ! |
Unrestricted file upload
Code injection
RCE |
NA |
Quentin Roland (@ROLANDQuentin2) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
983 | Gcash Vulnerability Walkthrough |
Android
Insecure deeplink
Insecure intent |
Gcash |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
982 | Reflected cross-site scripting vulnerability in Crealogix EBICS implementation |
Reflected XSS |
CREALOGIX AG |
Tobias Ospelt (@floyd_ch) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
981 | VMware vCenter Server Platform Services Controller Unsafe Deserialization vulnerability |
Insecure deserialization
Security code review |
VMware |
Marcin %27Icewall%27 Noga (@_Icewall) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
980 | [Hacking Banks] Broken Access Control Vulnerability in Banking application [PART I] |
Broken Access Control
Android |
NA |
Abdelhak Kharroubi |
Bug Bounty | 2022-10-10 | 2023-06-13 |
979 | Enter "Sandbreak" - Vulnerability In vm2 Sandbox Module Enables Remote Code Execution (CVE-2022-36067) |
RCE
Sandbox bypass |
vm2 |
Oxeye (@OxeyeSecurity) |
Bug Bounty | 2022-10-10 | 2023-06-13 |