903 | SSD Advisory – Galaxy Store Applications Installation/Launching without User Interaction |
XSS |
Samsung |
- |
Bug Bounty | 2022-10-26 | 2023-06-13 |
902 | Attacking The Software Supply Chain With A Simple Rename |
Repojacking
Supply chain attack |
GitHub |
Aviad Gershon (@aviadgershon) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
901 | SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri |
iOS
MacOS
Bluetooth
Local Privilege Escalation
TCC bypass |
Apple |
Guilherme Rambo (@_inside) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
900 | Client Side Desync Attack (CL.0 Request Smuggling) — Bounty of $150 |
HTTP Request Smuggling
Client-Side Desync attack |
NA |
Bodhendu Panda |
Bug Bounty | 2022-10-26 | 2023-06-13 |
899 | Hijacking AUR Packages by Searching for Expired Domains |
Subdomain takeover
Supply chain attack |
NA |
Joren Vrancken |
Bug Bounty | 2022-10-26 | 2023-06-13 |
898 | RC4 Is Still Considered Harmful |
Kerberos
MiTM
Local Privilege Escalation
Downgrade attack |
Microsoft (Windows) |
James Forshaw (@tiraniddo) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
897 | Misconfigured AWS S3 Bucket (Information Disclosure & Subdomain Takeover) |
AWS misconfiguration |
NA |
Gokhan Guzelkokar (@gkhck_) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
896 | A 250$ CSS Injection — My First Finding on Hackerone! |
CSS injection |
NA |
Dsonbacker |
Bug Bounty | 2022-10-27 | 2023-06-13 |
895 | Visual Studio Code Jupyter Notebook RCE |
RCE
XSS
Arbitrary file read
Electron |
Microsoft |
Luca Carettoni (@lucacarettoni) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
894 | AWS SSRF to Root on production instance — A bug worth 1.75Lacs |
SSRF
RCE
Password reset |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
893 | Abusing Windows’ tokens to compromise Active Directory without touching LSASS |
Local Privilege Escalation
Windows
Active Directory Privilege Escalation |
NA |
Aurélien Chalot (@Defte_) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
892 | RCE docker api, but … |
RCE
Docker daemon misconfiguration |
NA |
nanwn |
Bug Bounty | 2022-10-28 | 2023-06-13 |
891 | Blind SSRF in Skype (Microsoft) |
Blind SSRF |
Microsoft |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
890 | CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities |
RCE
Phar deserialization
Reflected XSS
XPATH injection
Path traversal
LFI |
Juniper |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
889 | Technical Analysis of Windows CLFS Zero-Day Vulnerability CVE-2022-37969 - Part 1: Root Cause Analysis |
Local Privilege Escalation
Windows |
Microsoft |
Zscaler Threatlabz (@Threatlabz) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
888 | How i was able to get free money via sending negative tokens |
Logic flaw
Payment tampering |
NA |
Mohamed Anani (@0xM5awy) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
887 | Exploiting Static Site Generators: When Static Is Not Actually Static |
SSRF
XSS
Security code review |
Netlify
Gatsby |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
886 | Old RCE worth $3362. |
RCE |
NA |
nanwn |
Bug Bounty | 2022-10-30 | 2023-06-13 |
885 | 2FA Bypass due to information disclosure & Improper access control. |
DoS
MFA bypass |
NA |
Akash Hamal (@AkashHamal0x01) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
884 | Vulnerabilities In Apache Batik Default Security Controls – SSRF And RCE Through Remote Class Loading |
SSRF
RCE |
Apache Batik |
Piotr Bazydło (@chudypb) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
883 | A tale of a simple Apple kernel bug |
Out-of-bounds Read
Memory corruption
MacOS
iOS |
Apple |
Jordy Zomer (@pwningsystems) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
882 | Blind SQL Injection on Delete Request |
Blind SQL injection |
NA |
Jawad Mahdi (@hunter0x1) |
Bug Bounty | 2022-10-30 | 2023-06-13 |
881 | Safari is hot-linking images to semi-random websites |
Browser hacking
XSS |
Apple |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
880 | urlscan.io%27s SOAR spot: Chatty security tools leaking private data |
Information disclosure |
NA |
Fabian Bräunlein |
Bug Bounty | 2022-11-01 | 2023-06-13 |
879 | CVE−2022-3602: Punycode buffer overflow in OpenSSL |
Memory corruption
DoS |
OpenSSL |
Colm MacCárthaigh (@colmmacc) |
Bug Bounty | 2022-11-01 | 2023-06-13 |