928 | Bypassing Mimecast URL and File Inspection |
Secure Email Gateway bypass
Logic flaw |
Mimecast |
Patrick Sayler (@psaYler) |
Bug Bounty | 2022-10-20 | 2023-06-13 |
927 | SHA-3 Buffer Overflow |
Buffer Overflow
Memory corruption
Cryptographic issues |
XKCP
Apple
Python
PHP
PyPy
SHA3 for Ruby |
Nicky Mouha |
Bug Bounty | 2022-10-20 | 2023-06-13 |
926 | Reverse Engineering the Apple Multipeer Connectivity Framework |
Authorization flaw
Reverse engineering
Networking |
Apple |
Simone Margaritelli (@evilsocket) |
Bug Bounty | 2022-10-20 | 2023-06-13 |
925 | The Curious Case Of The Password Database |
Cryptographic issues |
Zoho (ManageEngine) |
Travis Kaun (@W9HAX) |
Bug Bounty | 2022-10-20 | 2023-06-13 |
924 | Google VRP — [Insecure Direct Object Reference] $3133.70 |
IDOR |
Google |
Caesar Evan Santoso |
Bug Bounty | 2022-10-20 | 2023-06-13 |
923 | $1,000+ P1: PII Disclosure W/ IDOR |
IDOR |
NA |
Graham Zemel (@grahamzemel) |
Bug Bounty | 2022-10-21 | 2023-06-13 |
922 | Sail away, sail away, sail away |
RCE
Privilege escalation |
NA |
Reino Mostert |
Bug Bounty | 2022-10-21 | 2023-06-13 |
921 | Broken Link Hijacking — My Second Finding on Hackerone! |
Broken link hijacking |
NA |
mehedishakeel (@mehedishakeel) |
Bug Bounty | 2022-10-23 | 2023-06-13 |
920 | How I Found Three Credentials Leak on One Google Dork on Bugcrowd program |
Information disclosure |
Cengage |
Ittipatjitrada (@IttipatJitrada) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
919 | Missing Authentication in ZKTeco ZEM/ZMM Web Interface |
Missing authentication |
ZKTeco |
RedTeam Pentesting (@RedTeamPT) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
918 | Finding Multiple Security Issues on Agorapulse |
Log4shell
RCE
Information disclosure
Broken Access Control
Privilege escalation |
Agorapulse |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
917 | Atlassian Jira Align, Version 10.107.4 Advisory |
SSRF
Broken Access Control
Privilege escalation |
Atlassian |
Jacob Shafer (@fibbot) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
916 | How I Found A Simple Stored XSS |
Stored XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-10-24 | 2023-06-13 |
915 | SSRF & LFI In Uploads Feature |
SSRF
LFI |
NA |
Raymond Lind |
Bug Bounty | 2022-10-24 | 2023-06-13 |
914 | 5000$ for Apple Stored Xss And Another Blind Xss Still under review |
Blind XSS |
Apple |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
913 | Remote Code Execution by Abusing Apache Spark SQL |
SQL injection
RCE |
NA |
Colin McQueen |
Bug Bounty | 2022-10-24 | 2023-06-13 |
912 | Stranger Strings: An exploitable flaw in SQLite |
Memory corruption
Buffer Overflow
DoS |
SQLite |
Andreas Kellas |
Bug Bounty | 2022-10-25 | 2023-06-13 |
911 | The Logging Dead: Two Event Log Vulnerabilities Haunting Windows |
DoS |
Microsoft |
Dolev Taler |
Bug Bounty | 2022-10-25 | 2023-06-13 |
910 | Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager |
RCE
Insecure deserialization
Security code review |
VMware |
Sina Kheirkhah (@SinSinology) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
909 | Support supports a Hacker |
Social engineering
Spoofing
Authorization flaw
Account takeover |
NA |
mechboy (@mechboy_) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
908 | Chaining multiple vulnerabilities for credential stealing |
CSRF
Self-XSS
XSS |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
907 | Microsoft SharePoint Server Post-Authentication Server-Side Request Forgery vulnerability |
SSRF |
Microsoft |
Li Jiantao (@CurseRed) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
906 | GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown |
OS command injection
Arbitrary file read
Information disclosure
Account takeover
Stored XSS
Lack of rate limiting
Weak credentials
Password policy bypass |
GL.iNet |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
905 | Stored XSS To Cookie Exfiltration |
Stored XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-10-26 | 2023-06-13 |
904 | SSRF Bug Leads To AWS Metadata Exposure |
SSRF |
NA |
Raymond Lind |
Bug Bounty | 2022-10-26 | 2023-06-13 |