803 | How i found 29 stored XSS in modern framework |
Stored XSS |
NA |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
802 | Email Graffiti: hacking old email |
Broken link hijacking |
Google (Youtube) |
Dylan Ayrey (@insecurenature) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
801 | Hacking Smartwatches for Spear Phishing |
IoT
Phishing
Android |
NA |
Cybervelia (@cybervelia) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
800 | My Account Takeover Writeup: $5000 |
Lack of rate limiting
Bruteforce |
NA |
MRD7 (@_mrd7_) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
799 | Fastly Subdomain Takeover $2000 |
Subdomain takeover |
NA |
ValluvarSploit (@ValluvarSploit) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
798 | Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs |
GraphQL
Security misconfiguration |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
797 | A Confused Deputy Vulnerability in AWS AppSync |
Confused deputy
Cloud
Privilege escalation |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
795 | SSD Advisory – NETGEAR R7800 AFPD PreAuth |
Memory corruption
Buffer Overflow |
Netgear |
- |
Bug Bounty | 2022-11-22 | 2023-06-13 |
794 | Interesting Stored XSS via meta data |
Stored XSS |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2022-11-22 | 2023-06-13 |
793 | SSRF via DNS Rebinding (CVE-2022–4096) |
SSRF
DNS rebinding
TOCTOU |
Appsmith |
Basavaraj Banakar (@basu_banakar) |
Bug Bounty | 2022-11-22 | 2023-06-13 |
792 | CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You |
RCE
DNS rebinding
Information disclosure |
Tailscale |
Jamie McClymont (@JJJollyjim) |
Bug Bounty | 2022-11-22 | 2023-06-13 |
791 | CVE-2021-40662 Chamilo LMS 1.11.14 RCE |
Stored XSS
CSRF
RCE |
Chamilo LMS |
Febin |
Bug Bounty | 2021-11-23 | 2023-06-13 |
790 | XSS Vulnerability Found in ConnectWise Remote Access Platform With Great Potential For Misuse by Scammers |
Stored XSS |
ConnectWise |
Nati Tal |
Bug Bounty | 2022-11-23 | 2023-06-13 |
789 | CVE-2022-32898: ANE_ProgramCreate() multiple kernel memory corruption |
Memory corruption
iOS
Kernel hacking |
Apple |
simo (@_simo36) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
788 | How I get +10 SQLi and +30 XSS via Automation Tool |
SQL injection
XSS |
NA |
Mahmoud Attia (@0xElkot) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
787 | Account Takeover in KAYAK |
Account takeover
Android
Insecure deeplink |
KAYAK |
Carlos Bello |
Bug Bounty | 2022-11-23 | 2023-06-13 |
786 | CVE-2022-40300: SQL Injection In Manageengine Privileged Access Management |
SQL injection |
Zoho (ManageEngine) |
Justin Hung |
Bug Bounty | 2022-11-23 | 2023-06-13 |
785 | Dodging OAuth origin restrictions for Firebase spelunking |
OAuth
Security misconfiguration
Authentication flaw |
NA |
Aditya Saligrama (@saligrama_a) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
784 | From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942) |
Authentication bypass
Kerberos
RCE
Privilege escalation
Security code review |
Intel |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
783 | Multiple vulnerabilities in H2O ≤ 3.32.1.3 |
Insecure deserialization
RCE
Arbitrary file read
Security code review |
H2O |
Clément Amic |
Bug Bounty | 2022-11-23 | 2023-06-13 |
782 | Contrast discovers zero-day flaw in popular Quarkus Java framework |
Drive-by attack
CSRF
RCE |
Quarkus |
Joseph Beeton |
Bug Bounty | 2022-11-23 | 2023-06-13 |
781 | Legally hacking a Government Satellite? |
Missing authentication
OS command injection
RCE |
NA |
RiotSecTeam (@RiotSecTeam) |
Bug Bounty | 2022-11-24 | 2023-06-13 |
780 | Hacker%27s Guide to Directory/Endpoint Enumeration |
40x bypass |
NA |
Inderjeet Singh (@3nc0d3dGuY) |
Bug Bounty | 2022-11-24 | 2023-06-13 |
779 | CVE-2022–43781 |
OS command injection
RCE |
Atlassian |
Petrus Viet (@VietPetrus) |
Bug Bounty | 2022-11-25 | 2023-06-13 |
778 | Able to Mass-change profile section leads to my first $BOUNTY$ |
HTML injection
IDOR
CSRF |
NA |
SYRINE |
Bug Bounty | 2022-11-25 | 2023-06-13 |