669 | My First Bug In Bugcrowd Platform |
Race condition |
NA |
EX_097 |
Bug Bounty | 2022-12-21 | 2023-06-13 |
668 | Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951) |
SSRF
Security code review |
Cisco |
smaury (@smaury92) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
667 | RCE on admin panel of web3 website |
RCE
Components with known vulnerabilities |
NA |
T VAMSHI |
Bug Bounty | 2022-12-21 | 2023-06-13 |
666 | Zero Click To Account Takeover (IDOR + XSS) |
IDOR
XSS
Account takeover |
NA |
Arman (@M7arm4n) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
665 | Delete any Video or Reel on Facebook (11,250$) |
IDOR |
Meta / Facebook |
Bassem Bazzoun (@bassemmbazzoun)) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
663 | Passwordless Persistence and Privilege Escalation in Azure |
Privilege escalation
Cloud
Azure AD |
Microsoft |
Andy Robbins (@_wald0) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
662 | How Race Condition helped me break Business Logic of the application |
Race condition |
NA |
Inderjeet Singh (@3nc0d3dGuY) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
661 | Multiple authenticated blind SQL Injections in Sage XRT Business Exchange application |
Blind SQL injection |
Sage |
Mickaël Benassouli (@mickaelweb) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
660 | Puckungfu: A NETGEAR WAN Command Injection |
OS command injection
Security code review |
Netgear |
McCaulay Hudson (@_mccaulay) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
659 | ACSESSED: Cross-tenant network bypass in Azure Cognitive Search |
Cloud
Cross-tenant vulnerability
Privilege escalation |
Microsoft (Azure) |
Emilien Socchi (@emiliensocchi) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
658 | ENLBufferPwn (CVE-2022-47949) |
Buffer Overflow
Memory corruption
RCE |
Nintendo |
PabloMK7 (@Pablomf6) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
657 | $350 XSS in 15 minutes |
DOM XSS
JSONP |
NA |
Anton (@therceman) |
Bug Bounty | 2022-12-23 | 2023-06-13 |
656 | Microsoft bug reports lead to ranking on Microsoft MSRC Quarterly Leaderboard (Q3 2022) |
XSS |
Microsoft |
Supakiad S. (@Supakiad_Mee) |
Bug Bounty | 2022-12-23 | 2023-06-13 |
655 | CRLF Injection — xxx$ — How was it possible for me to earn a bounty with the Cloudflare WAF? |
CRLF injection |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2022-12-24 | 2023-06-13 |
654 | Bypass Apple’s redirection process with the dot (“.”) character |
Open redirect |
Apple |
can1337 (@canmustdie) |
Bug Bounty | 2022-12-24 | 2023-06-13 |
652 | Unusual 403 Bypass to a full website takeover [External Pentest] |
403 bypass |
NA |
Viktor Mares |
Bug Bounty | 2022-12-25 | 2023-06-13 |
651 | How I Pwned 10 Admin Panels and got rewarded 8000$+? |
Information disclosure
Credential stuffing |
NA |
Inderjeet Singh (@3nc0d3dGuY) |
Bug Bounty | 2022-12-25 | 2023-06-13 |
650 | Authentication Bypass in Nexus manager (version 3.37.3–02) |
Components with known vulnerabilities
Authentication bypass
HTTP response manipulation |
NA |
SHARAN.K |
Bug Bounty | 2022-12-26 | 2023-06-13 |
649 | Uncovering a Bug I Found in Outlook: How Could an Account Has Been Compromised? |
XSS |
Microsoft |
Cem Onat Karagun |
Bug Bounty | 2022-12-26 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
647 | Turning Google smart speakers into wiretaps for $100k |
IoT
Wifi hacking |
Google |
Matt |
Bug Bounty | 2022-12-26 | 2023-06-13 |
646 | The OWASSRF + TabShell exploit chain |
SSRF
Path traversal
Sandbox escape |
Microsoft |
Rskvp93 (@rskvp93) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
645 | Stored XSS vulnerability in Microsoft booking |
Stored XSS
CSP bypass |
Microsoft |
Mrtechghost |
Bug Bounty | 2022-12-27 | 2023-06-13 |
644 | Hacking a .NET API in the real world |
LFI |
NA |
Dana Epp (@DanaEpp) |
Bug Bounty | 2022-12-27 | 2023-06-13 |