1944 | NPM might be executing malicious code in your CI without your knowledge |
RCE |
GitHub |
Rotem Bar (@rotembar) |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1935 | A phishing document signed by Microsoft – part 2 |
Phishing
RCE |
Microsoft |
Pieter Ceelen (@ptrpieter) |
Bug Bounty | 2022-01-07 | 2023-06-13 |
1931 | How did I find Log4j vulnerability via Static Code Analysis and receive €€€ bounty? |
Log4shell
RCE |
NA |
Pranav Gajjar (@Pranav_Gajjar_) |
Bug Bounty | 2022-01-10 | 2023-06-13 |
1929 | Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle%27s Shibboleth |
Session hijacking
Session management issue
Account takeover
RCE |
Moodle |
Johannes Moritz |
Bug Bounty | 2022-01-10 | 2023-06-13 |
1928 | Cross-Origin Resource Sharing (CORS) Misconfiguration leads to User’s PII leaks. |
CORS misconfiguration |
NA |
Tarikul Islam (@sa1tama0) |
Bug Bounty | 2022-01-10 | 2023-06-13 |
1926 | Attacking RDP from Inside: How we abused named pipes for smart-card hijacking, unauthorized file system access to client machines and more |
RCE |
Microsoft |
Gabriel Sztejnworcel (@sztejnworcel) |
Bug Bounty | 2022-01-11 | 2023-06-13 |
1918 | RCE In Adobe Acrobat Reader For Android(CVE-2021-40724) |
RCE
Path traversal
Android |
Google
Adobe |
sunny (@hulkvision) |
Bug Bounty | 2022-01-14 | 2023-06-13 |
1906 | The Tale of a Click leading to RCE |
RCE
SSRF |
CatchPoint |
Roni Carta (@0xLupin) |
Bug Bounty | 2022-01-18 | 2023-06-13 |
1894 | How I was able to take over accounts in websites deal with Github as an SSO provider |
Bruteforce
Lack of rate limiting
SSO
Email verification bypass
Account takeover |
NA |
Khaled Mohamed |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1887 | Technical Analysis of CVE-2022-22583: Bypassing macOS System Integrity Protection (SIP) |
MacOS
SIP bypass |
Apple |
Perception Point |
Bug Bounty | 2022-01-27 | 2023-06-13 |
1884 | The Story of an RCE on a Java Web Application |
Insecure deserialization |
NA |
LIL NIX (@Lil__Nix) |
Bug Bounty | 2022-01-27 | 2023-06-13 |
1882 | The Story of a RCE on a Java Web Application |
RCE
Insecure deserialization |
NA |
LIL NIX (@Lil__Nix) |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1881 | Command Injection in Google Cloud Shell |
RCE
OS command injection |
Google |
Ademar Nowasky Junior |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1872 | Remote Code Execution in .tgz File Upload |
RCE
Unrestricted file upload |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-01-30 | 2023-06-13 |
1871 | Missing rate-limiting. How I was able to add any unowned phone number to my Facebook account? (Bounty: 5000 USD) |
OTP bruteforce
Lack of rate limiting |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2022-01-31 | 2023-06-13 |
1865 | CVE-2021-44142: Details On A Samba Code Execution Bug Demonstrated At Pwn2Own Austin |
Memory corruption
RCE |
NA |
Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss) |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1863 | No Rate Limiting on OTP sending |
Bruteforce
Lack of rate limiting |
NA |
nOOb_mAsTeR |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1855 | HigherLogic Community RCE Vulnerability |
Insecure deserialization
RCE |
8x8
IBM |
0daystolive (@0daystolive) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1853 | Write Up – Private Bug Bounty: RCE In EC2 Instance Via SSH With Private Key Exposed On Public Github Repository – $xx,000 USD |
Information disclosure |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1851 | How I bypassed PHP functions to read sensitive files on server |
Components with known vulnerabilities
RCE |
NA |
Kailash (@corrupted_brain) |
Bug Bounty | 2022-02-04 | 2023-06-13 |
1836 | WordPress < 5.8.3 - Object Injection Vulnerability |
Object injection
RCE |
WordPress |
Simon Scannell (@scannell_simon) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1823 | How i made 15k$ from Remote Code Execution Vulnerability |
Code injection
RCE
Self-XSS |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2022-02-13 | 2023-06-13 |
1819 | Advisory: Western Digital My Cloud Pro Series PR4100 RCE |
RCE
OS command injection |
Western Digital |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1816 | Hunting for bugs in VMware: View Planner and vRealize Business for Cloud |
RCE |
VMware |
Mikhail Klyuchnikov (@__Mn1__) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1810 | CVE-2022-0478 - WooCommerce Event-Manager Plugin SQL Injection |
SQL injection
Security code review |
Automattic (WooCommerce) |
Castilho (@castilho101) |
Bug Bounty | 2022-02-16 | 2023-06-13 |