616 | PandoraFMS - Pre-Auth Remote Code Execution |
RCE
Path traversal
Arbitrary file upload
LFI
Security code review |
PandoraFMS |
esj4y (@esj4y) |
Bug Bounty | 2023-01-06 | 2023-06-13 |
615 | I scanned every package on PyPi and found 57 live AWS keys |
Information disclosure |
Amazon
Intel
Stanford
The Australian Government |
Tom Forbes |
Bug Bounty | 2023-01-06 | 2023-06-13 |
614 | Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability |
CORS misconfiguration |
Google |
Borna Nematzadeh (@LogicalHunter) |
Bug Bounty | 2023-01-06 | 2023-06-13 |
613 | Advanced CSRF Exploitation |
CSRF
Stored XSS |
NA |
Sandro Einfeldt |
Bug Bounty | 2023-01-07 | 2023-06-13 |
612 | The Bug That Kept On Giving :: PaymentBypass :: QR CODE |
Payment bypass |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-01-07 | 2023-06-13 |
611 | The SSRF that Brought down a Server |
SSRF
DoS |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-01-07 | 2023-06-13 |
610 | Bug hunting: Open access to S3 bucket |
AWS misconfiguration |
NA |
Raghul Raj |
Bug Bounty | 2023-01-09 | 2023-06-13 |
609 | Uploading the Webshell using filename of Content-Disposition Header Story! |
Unrestricted file upload
Arbitrary file write |
NA |
Yashar Mohagheghi |
Bug Bounty | 2023-01-09 | 2023-06-13 |
608 | Meta Quest: Attacker could make any Oculus user to follow (subscribe) him without any approval |
IDOR
Authorization flaw |
Meta / Facebook |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
607 | Lexmark MC3224adwe RCE exploit |
RCE
SSRF
Printer hacking
Unrestricted file upload
Local Privilege Escalation |
Lexmark |
blasty (@bl4sty) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
606 | Hacking Hackers for fun and profit |
Self-XSS
Blind XSS |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
605 | Full Team Takeover |
Broken Access Control
Logic flaw |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
603 | Practical Example Of Client Side Path Manipulation |
Client-side Path Traversal |
NA |
Antoine Roly (@aroly) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
602 | Full Team Takeover |
Account takeover
Broken Access Control |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
601 | How I Earned $1000 From Business Logic Vulnerability (account takeover) |
Logic flaw
Account takeover |
NA |
andika |
Bug Bounty | 2023-01-10 | 2023-06-13 |
600 | SSD Advisory – MacOS Mozilla Firefox Download Protections Were Bypassed By .atloc / .ftploc Files |
Local Privilege Escalation |
Mozilla (Firefox) |
Dohyun Lee |
Bug Bounty | 2023-01-11 | 2023-06-13 |
599 | Google Chrome “SymStealer” Vulnerability: How to Protect Your Files from Being Stolen |
Local Privilege Escalation
Browser hacking
Symbolic link following |
Google (Chrome & Chromium) |
Ron Masas (@RonMasas) |
Bug Bounty | 2023-01-11 | 2023-06-13 |
598 | Client-Side SSRF to Google Cloud Project Takeover [Google VRP] |
SSRF
CSRF
Open redirect |
Google |
Dohyun Lee |
Bug Bounty | 2023-01-12 | 2023-06-13 |
597 | DER Entitlements: The (Brief) Return of the Psychic Paper |
iOS
MacOS
Local Privilege Escalation |
Apple |
Ivan Fratric (@ifsecure) |
Bug Bounty | 2023-01-12 | 2023-06-13 |
596 | SSH key injection in Google Cloud Compute Engine [Google VRP] |
OS command injection
RCE |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-12 | 2023-06-13 |
595 | Bad things come in large packages: .pkg signature verification bypass on macOS |
Local Privilege Escalation
GateKeeper bypass
SIP bypass
MacOS |
Apple |
Sector 7 (@sector7_nl) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
594 | Bypassing authorization in Google Cloud Workstations [Google VRP] |
Account takeover
OAuth
URL validation bypass |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
593 | Exploiting Application Logic to Phish Internal Mailing Lists |
Phishing |
NA |
Tanner Emek (@itscachemoney) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
592 | How Browser’s Save As Feature might lead to Code Execution (CVE-2022–45415) |
RCE
Browser hacking |
Mozilla (Firefox) |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2023-01-14 | 2023-06-13 |