853 | Some Tips to Finding IDORs more easily and Fixing them |
IDOR |
NA |
Xenon |
Bug Bounty | 2022-11-08 | 2023-06-13 |
852 | Netgear Nighthawk R7000P AWS_JSON Unauthenticated Double Stack Overflow Vulnerability |
Memory corruption |
Netgear |
Jean-Jamil Khalife |
Bug Bounty | 2022-11-09 | 2023-06-13 |
851 | My First Account Takeover |
Account takeover
Logic flaw |
NA |
JAI NIRESH J |
Bug Bounty | 2022-11-09 | 2023-06-13 |
850 | Jit-Picking: Differential Fuzzing of JavaScript Engines |
Browser hacking |
Mozilla |
Lukas Bernhard (@bernhl) |
Bug Bounty | 2022-11-09 | 2023-06-13 |
849 | Chaining Path Traversal with SSRF to disclose internal git repo data in a Bank Asset |
SSRF
Path traversal |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
848 | Sleep SQL injection on Name Parameter While Updating Profile |
SQL injection |
NA |
Umer Yousuf |
Bug Bounty | 2022-11-10 | 2023-06-13 |
847 | Google VRP (Acquisitions) — [Insecure Direct Object Reference] 2nd |
IDOR |
Google |
Caesar Evan Santoso |
Bug Bounty | 2022-11-10 | 2023-06-13 |
846 | Accidental $70k Google Pixel Lock Screen Bypass |
Lock screen bypass
Authentication bypass
Android |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-10 | 2023-06-13 |
845 | How Sigstore quickly patched an upstream vulnerability |
OAuth
Account takeover
Phishing |
Sigstore
dex |
Joern Schneeweisz |
Bug Bounty | 2022-11-10 | 2023-06-13 |
844 | Unit 42 Finds Three Vulnerabilities in OpenLiteSpeed Web Server |
RCE
OS command injection
Path traversal
Local Privilege Escalation |
LiteSpeed |
Artur Avetisyan (@3v1LMonk3y) |
Bug Bounty | 2022-11-10 | 2023-06-13 |
843 | Discovering vendor-specific vulnerabilities in Android |
Android |
Samsung
Google |
Oversecured (@OversecuredInc) |
Bug Bounty | 2022-11-10 | 2023-06-13 |
842 | Windows Kernel: Exploit CVE-2022-35803 in Common Log File System |
Windows
Local Privilege Escalation
Type confusion |
Microsoft |
luckyu (@uuulucky) |
Bug Bounty | 2022-11-11 | 2023-06-13 |
841 | From Shodan Dork to Grafana 📊Local File Inclusion |
LFI
Old components with known vulnerabilities |
NA |
Anurag__Verma |
Bug Bounty | 2022-11-11 | 2023-06-13 |
840 | Security and Privacy Failures in Popular 2FA Apps |
Cryptographic issues |
LastPass
Google
Twilio
Microsoft
Duo
Salesforce
Latch
Zoho |
Conor Gilsenan |
Bug Bounty | 2022-11-11 | 2023-06-13 |
839 | Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures |
Signature bypass
Signature forgery
Cryptographic issues
Windows |
Microsoft |
Simon Rohlmann |
Bug Bounty | 2022-11-11 | 2023-06-13 |
838 | Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js |
RCE
Prototype pollution
DoS |
Rocket.Chat
NPM CLI
Parse Server
Node.js |
Mikhail Shcherbakov |
Bug Bounty | 2022-11-11 | 2023-06-13 |
837 | CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS |
MacOS
Local Privilege Escalation
SIP bypass |
Apple |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-11-11 | 2023-06-13 |
836 | Finding Reflected XSS In A Strange Way |
XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-11-11 | 2023-06-13 |
835 | How i get $100 in just 10 minutes ! |
Race condition |
NA |
Jody ritonga |
Bug Bounty | 2022-11-13 | 2023-06-13 |
834 | Path Traversal Vulnerability in Payara Platform |
Path traversal |
Payara |
Michael Baer |
Bug Bounty | 2022-11-14 | 2023-06-13 |
833 | CVE-2022-32929 - Bypass iOS backup%27s TCC protection |
Local Privilege Escalation
TCC bypass
MacoS
iOS |
Apple |
Csaba Fitzl (@theevilbit) |
Bug Bounty | 2022-11-14 | 2023-06-13 |
832 | SSD Advisory – Cisco Secure Manager Appliance remediation_request_utils SQL Injection Remote Code Execution |
SQL injection
RCE
Security code review |
Cisco |
- |
Bug Bounty | 2022-11-14 | 2023-06-13 |
831 | SSD Advisory – Cisco Secure Manager Appliance jwt_api_impl Hardcoded JWT Secret Elevation of Privilege |
Hardcoded credentials
Security code review
JWT
Privilege escalation |
Cisco |
- |
Bug Bounty | 2022-11-14 | 2023-06-13 |
830 | Firebase: Insecure by Default (feat. that one time our classmates tried to sue us) |
Hardcoded API keys |
Fizz |
Aditya Saligrama (@saligrama_a) |
Bug Bounty | 2022-11-14 | 2023-06-13 |
829 | Winning QR with DOM-Based XSS | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-11-15 | 2023-06-13 |