953 | [CVE-2022-1786] A Journey To The Dawn |
Use-After-Free
Memory corruption
Local Privilege Escalation |
Google (kCTF)
Linux Kernel Organization |
kylebot (@ky1ebot) |
Bug Bounty | 2022-10-15 | 2023-06-13 |
952 | My First Critical Bug In HackerOne Platform |
HTTP request smuggling |
NA |
EX_097 |
Bug Bounty | 2022-10-16 | 2023-06-13 |
951 | How I Got $10,000 From GitHub For Bypassing Filtration of HTML tags |
XSS |
GitHub |
Saajan Bhujel (@saajanbhujel) |
Bug Bounty | 2022-10-16 | 2023-06-13 |
950 | Toner Deaf – Printing your next persistence (Hexacon 2022) |
Path traversal
Arbitrary file write
RCE
Printer hacking |
Lexmark |
Alex Plaskett (@alexjplaskett) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
949 | Facebook SMS Captcha Was Vulnerable to CSRF Attack |
CSRF |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
948 | Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution |
RCE |
ICONICS |
Sector 7 (@sector7_nl) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
947 | Analysis of a Remote Code Execution (RCE) Vulnerability in Cobalt Strike 4.7.1 |
RCE
XSS |
HelpSystems |
Rio (@0x09AL) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
946 | Guest Blog Post - Memory corruption vulnerabilities in Edge |
Browser hacking
Memory corruption
Use-After-Free
Out-of-bounds Read
Out-of-bounds Write |
Microsoft |
David Erceg (@david_erceg) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
945 | CVE 2022–24082, RCE in the PEGA Platform — Discovery, Remediation & Technical Details (Long Live JMX!!!) |
RCE
JMX |
PEGA |
Marcin Wolak |
Bug Bounty | 2022-10-17 | 2023-06-13 |
944 | PHP Filters Chain: What Is It And How To Use It |
Insecure deserialization
PHP filter chain |
Laravel |
Rémi Matasse (@_remsio_) |
Bug Bounty | 2022-10-18 | 2023-06-13 |
943 | Basic recon to RCE III |
RCE
OS command injection |
NA |
Joshua Martinelle (@J0_mart) |
Bug Bounty | 2022-10-18 | 2023-06-13 |
942 | The Danger of Falling to System Role in AWS SDK Client |
Cloud
Privilege escalation
Security misconfiguration |
NA |
Fracensco Lacerenza (@lacerenza_fra) |
Bug Bounty | 2022-10-18 | 2023-06-13 |
941 | Remote Code Execution in Melis Platform |
RCE
Path traversal
Insecure deserialization
Security code review |
Melis Platform |
Karim El Ouerghemmi |
Bug Bounty | 2022-10-18 | 2023-06-13 |
940 | Yet Another Telerik UI Revisit |
Cryptographic issues
RCE |
Progress (Telerik) |
Paul Mueller |
Bug Bounty | 2022-10-19 | 2023-06-13 |
939 | Vulnerabilities in Tenda%27s W15Ev2 AC1200 Router |
OS command injection
Buffer Overflow
Memory corruption
Stored XSS
Authorization flaw
Information disclosure |
Tenda |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
938 | Found vulnaribility on subdomain of nasa.gov simply using censys |
Exposed registration page |
NASA |
hacker_might |
Bug Bounty | 2022-10-19 | 2023-06-13 |
937 | Scan QR Code and Got Hacked (CVE-2021–43530 : UXSS on Firefox Android Version) |
Universal XSS
Android |
Mozilla |
hafiizh |
Bug Bounty | 2022-10-19 | 2023-06-13 |
936 | CVE-2022-3236: Sophos Firewall User Portal and Web Admin Code Injection |
RCE
Code injection
Security code review |
Sophos |
Guy Lederfein (@glederfein) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
935 | Microsoft Office Online Server Remote Code Execution |
SSRF
RCE |
Microsoft |
Manish Tanwar (@IndiShell1046) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
934 | FabriXss (CVE-2022-35829): How We Managed to Abuse a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer |
CSTI
Stored XSS |
Microsoft |
Lidor Ben Shitrit |
Bug Bounty | 2022-10-19 | 2023-06-13 |
933 | Second Order XXE Exploitation |
XXE
Arbitrary file read |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
932 | HTTP/3 connection contamination: an upcoming threat? |
HTTP connection contamination |
NA |
James Kettle (@albinowax) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
931 | A New Attack Surface on MS Exchange Part 4 - ProxyRelay! |
RCE
Privilege escalation |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
930 | 23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite |
JWT
Authentication bypass
Arbitrary file write
Unrestricted file upload |
NA |
Souhaib Naceri (@h4x0r_dz) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
929 | Potential Remote Code Execution Vulnerability Discovered In HSQLDB |
RCE
Security code review |
HSQL Development Group (HSQLDB) |
Code Intelligence (@CI_Fuzz) |
Bug Bounty | 2022-10-19 | 2023-06-13 |