1592 | 2FA Secret value disclosure leads to 2FA Bypass - Bug Bounty Writeup |
MFA bypass
Information disclosure |
NA |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1590 | Contact Point Deanonymization Vulnerability in Meta |
Information disclosure |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1580 | How i found a vulnerability that leads to access any users’ sensitive data and got $500 |
Information disclosure |
Flickr |
Mr Robert | Ahmed M Hassan (@Mr_Robert20) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1573 | How We hacked (bypassed) Admin Panel just by JS file |
Information disclosure |
NA |
Zhenwar Hawlery (@zhenwarx) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1571 | Cloudflare Pages, part 1: The fellowship of the secret |
Command injection
Container escape
Bash Path injection
RCE
Local Privilege Escalation
Information disclosure |
Cloudflare |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1570 | The $16,000 Dev Mistake |
Information disclosure |
NA |
Daniel Marte (@Masonhck3571) |
Bug Bounty | 2022-05-07 | 2023-06-13 |
1568 | P1 Bug — PII information disclosure |
Information disclosure
IDOR |
NA |
Huntersherlock |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1556 | Forging OAuth tokens using discovered client id and client secret |
Information disclosure
Account takeover |
NA |
Basyouni (@AshrafBasyoni4) |
Bug Bounty | 2022-05-12 | 2023-06-13 |
1542 | From Wayback to Account Takeover |
Information disclosure
Account takeover |
Plex |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2022-05-19 | 2023-06-13 |
1541 | How I was able to access IBM internal documents |
Information disclosure
IDOR |
IBM |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2022-05-19 | 2023-06-13 |
1512 | Exploiting iOS app for fun and profit |
Account takeover
Information disclosure |
NA |
Bijan Murmu (@0xbijan) |
Bug Bounty | 2022-05-29 | 2023-06-13 |
1489 | De-Anonymization attacks against Proton services |
Privacy issue
Information disclosure
HTML injection
Local Privilege Escalation |
Proton AG |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1486 | Chaining vulnerabilities to criticality in Progress WhatsUp Gold |
SSRF
Local File Disclosure
Information disclosure |
Progress (WhatsUp Gold) |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1476 | Finding vulnerabilities in curl 7.83.0 without reading a single-line of C code |
SSRF
Information disclosure
HSTS bypass |
Internet Bug Bounty (curl) |
Haxatron (@Haxatron1) |
Bug Bounty | 2022-06-12 | 2023-06-13 |
1472 | 500$ Account Takeover |
Account takeover
Information disclosure
HTTP response manipulation |
Xsolla |
Hemant Kumar |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1468 | 403 bypass on a fortune 100 financial institution (P3) |
Information disclosure
Authorization flaw
Forced browsing |
NA |
Damaidec |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1449 | Personal Access Token Disclosure in Asana Desktop Application |
Information disclosure
Hardcoded credentials |
Asana |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2022-06-18 | 2023-06-13 |
1448 | Account Takeover by OTP bypass |
Information disclosure
Client-side enforcement of server-side security
OTP bypass
Account takeover |
NA |
Vaibhav Kumar Srivastava |
Bug Bounty | 2022-06-19 | 2023-06-13 |
1440 | We were vulnerable - how a security company could have vulns |
Broken Access Control
Authorization flaw
Information disclosure |
Volkis |
Soman Verma |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1430 | Bug: Cisco IOS SNMPv3 ACL Issues |
Information disclosure |
Cisco |
Gerry Gosselin (@ggPixelHealth) |
Bug Bounty | 2022-06-26 | 2023-06-13 |
1401 | Penetration Testing Firebase Web Applications |
Firebase
Information disclosure |
NA |
Bhashit Pandya (@x30r_) |
Bug Bounty | 2022-07-03 | 2023-06-13 |
1391 | PII Disclosure of Apple Users ($10k) |
IDOR
Lack of rate limiting
Bruteforce
Information disclosure |
Apple |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1384 | How I earned 200$ in Bug Bounty Program |
Information disclosure |
NA |
Idan Malihi |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1367 | Abusing URL Shortners for fun and profit |
Information disclosure
Account takeover
IDOR |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1361 | Good Recon Leads To Senssitive Accounts |
Information disclosure
Username enumeration |
NA |
Milanjain |
Bug Bounty | 2022-07-15 | 2023-06-13 |