777 | Exploiting an N-day vBulletin PHP Object Injection Vulnerability |
PHP Object Injection
Security code review |
vBulletin |
Egidio Romano / EgiX |
Bug Bounty | 2022-11-26 | 2023-06-13 |
776 | Hacking Dutch Government-Broken Authentication To Full Website Takeover (P1) |
Exposed registration page |
Dutch Government |
V1dr4X |
Bug Bounty | 2022-11-26 | 2023-06-13 |
775 | How I hacked into a government e-learning website |
IDOR
Account takeover |
NA |
iamgk808 (@iamgk808) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
774 | Exploiting CORS Misconfigurations |
CORS misconfiguration
CSRF
XST |
Apple
Google
Mozilla (Firefox)
WHATWG |
scarlet / attack ships on fire |
Bug Bounty | 2022-11-26 | 2023-06-13 |
773 | WebView XSS, account takeover |
Webview XSS
Android
Account takeover
Improper Export of Android Application Components |
NA |
shafou |
Bug Bounty | 2022-11-26 | 2023-06-13 |
772 | A great weekend hack(worth $8k) |
SQL injection
IDOR
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
771 | [Hacking Bank] The Second Story of Finding Critical Vulnerabilities on Banking Application |
Android
Hardcoded credentials
IDOR |
NA |
Abdelhak Kharroubi |
Bug Bounty | 2022-11-26 | 2023-06-13 |
770 | A Real World Example Of Classic Remote Command Execution (RCE) |
OS command injection
XSS
RCE |
NA |
Bhashit Pandya (@x30r_) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
769 | Automating Unsolicited Richard Pics; Pwning 60,000 Digital Picture Frames |
IDOR
Broken Access Control
Android
IoT |
Ourphoto |
Nick M (@1oopho1e) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
768 | Access Any Owner Account without Authentication (Auth bypass + 2FA bypass) |
Authentication bypass
MFA bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
767 | Firebase Exploit bug bounty |
Security misconfiguration
Firebase |
NA |
Damaidec |
Bug Bounty | 2022-11-27 | 2023-06-13 |
766 | Unique Rate limit bypass worth 1800$ |
Rate limiting bypass
Captcha bypass |
NA |
Manav Bankatwala (@ManavBankatwala) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
765 | 2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation |
Authentication bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
764 | Multiple Vulnerabilities found in Airtel Android Application |
Arbitrary Code Execution
URL validation bypass
Symlink attack
XSS
Android
Webview |
Airtel
Google |
Gaurang Bhatnagar (@hax0rgb) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
763 | The Untold SendBird Misconfigurations |
Broken Access Control |
SendBird |
LTiDi (@dunglt140150) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
762 | Improper error handling leads to exposing internal tokens |
Information disclosure |
NA |
Agnieszka Pietruczuk |
Bug Bounty | 2022-11-28 | 2023-06-13 |
761 | Broken access control + misconfiguration = Beautiful privilege escalation |
Broken Access Control
Privilege escalation |
NA |
Hossam Mesbah (@m359ah) |
Bug Bounty | 2022-11-28 | 2023-06-13 |
760 | discord.exe – Improper Input Validation |
Security code review
Local Privilege Escalation
Phishing |
Discord |
RiotSecTeam (@RiotSecTeam) |
Bug Bounty | 2022-11-28 | 2023-06-13 |
759 | Cross-Site Scripting in CodeIgniter version 3.1.13 |
Reflected XSS
Security code review |
CodeIgniter |
Antoine Cervoise |
Bug Bounty | 2022-11-29 | 2023-06-13 |
758 | VoIP Spoofing (Intigriti) 1,250€ |
VoIP
Spoofing |
NA |
0xJin (@0xJin) |
Bug Bounty | 2022-11-29 | 2023-06-13 |
756 | Brocade Fabric OS ≤ v8.0.2c rbash escape to read system files |
rbash escape
Local Privilege Escalation |
Broadcom |
Bitcrack (@bitcrack_cyber) |
Bug Bounty | 2022-11-29 | 2023-06-13 |
755 | Unrestricted file upload in Rocket TRUfusion Enterprise <= 7.9.6.0 |
Unrestricted file upload
Security code review
RCE |
Rocket Software |
Mehdi Elyassa |
Bug Bounty | 2022-11-30 | 2023-06-13 |
754 | Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video |
Stored XSS |
TikTok |
Aidil Arief |
Bug Bounty | 2022-11-30 | 2023-06-13 |
752 | VLC : Integer overflow in vnc module <= 3.0.18 CVE-2022-41325 |
Memory corruption
Integer overflow |
VLC |
0xMitsurugi |
Bug Bounty | 2022-11-30 | 2023-06-13 |
751 | XSS on account.leagueoflegends.com via easyXDM [2016] |
XSS
postMessage |
Riot Games |
Luke Young (@TheBoredEng) |
Bug Bounty | 2022-12-01 | 2023-06-13 |