1359 | Authorization token leak from verify email endpoint |
Account takeover
Information disclosure |
NA |
Vengeance |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1353 | A Story Of My First Bug Bounty |
Information disclosure |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2022-07-17 | 2023-06-13 |
1352 | FFUF-ing RECON, or how to get to P1–P3 from a slightly different recon |
vHost misconfiguration
403 bypass
Information disclosure |
NA |
Vuk Ivanovic |
Bug Bounty | 2022-07-17 | 2023-06-13 |
1346 | Authomize Discovers PassBleed Password Stealing and Impersonation Risks in Okta |
Sensitive data sent over an unencrypted channel
Authorization flaw
Information disclosure |
Okta |
Authomize (@Authomize) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1343 | Logging Passwords in Plaintext in Azure Arc |
Information disclosure
Local Privilege Escalation
Cloud |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1330 | How I was able to Take over a support chat using leaked Keys |
Information disclosure |
NA |
Pliskin |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1325 | $$$ bounty in less 3 minutes from a google dork |
Information disclosure |
NA |
Steiner254 (@steiner254) |
Bug Bounty | 2022-07-23 | 2023-06-13 |
1319 | With Management Comes Risk: Finding Flaws in FileWave MDM |
Authentication bypass
Hardcoded credentials
Information disclosure |
Filewave |
Claroty%27s Team82 (@Claroty) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1315 | Digging JS files to find BUGs |
IDOR
Information disclosure |
NA |
Adnan Malik (@adnanmalikinfo) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1282 | Elasticsearch A Easy Win For Bug Bounty Hunters || How To Find and Report |
Information disclosure |
NA |
Tamim Hasan (@tamimhasan404) |
Bug Bounty | 2022-08-03 | 2023-06-13 |
1264 | From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager |
Authentication bypass
Information disclosure
Local Privilege Escalation |
VMware |
Steven Seeley (@steventseeley) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1258 | 403 Forbidden Bypass Leading to Admin Endpoint Access. |
403 bypass
Information disclosure |
NA |
Christian Dray (@G0ds0nXY) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1245 | IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit |
Authentication bypass
Information disclosure
CSRF
RCE
Local Privilege Escalation |
VMware |
Steven Seeley (@steventseeley) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1230 | Story of 5000$ bounty for Grafana Panel Access in Apple |
Missing authentication
Information disclosure |
Apple |
hckerl00 (@lokeshg62498939) |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1226 | Hacking Zyxel IP cameras to gain a root shell |
Missing authentication
DoS
Information disclosure
Local Privilege Escalation |
Zyxel |
Eric Urban |
Bug Bounty | 2022-08-14 | 2023-06-13 |
1220 | Salesforce bug hunting to Critical bug |
Information disclosure
Salesforce |
NA |
Vuk Ivanovic |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1211 | Monitoring Linux host metrics with the Node Exporter information disclosure $350 |
Information disclosure
Missing authentication |
Slack |
Dhamotharan (@Dhamu_offi) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1199 | Account takeover worth $1000 |
Account takeover
Authentication bypass
Information disclosure
Password reset |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1193 | How a Port scan got me Nokia Hall of Fame |
Missing authentication
Information disclosure |
Nokia |
Mani Sashank |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1189 | Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager |
Hardcoded credentials
Information disclosure |
SAP |
Arpine Maghakyan |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1185 | [CVE-2020-2733] JD Edwards EnterpriseOne Tools admin password not adequately protected |
Information disclosure |
Oracle |
Vahagn Vardanyan (@vah_13) |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1155 | My findings on Hack U.S Program |
Missing authentication
.git folder disclosure
Information disclosure |
U.S. Dept Of Defense |
Charansai |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1154 | IDOR at Login function leads to leak user’s PII data |
IDOR
Information disclosure |
NA |
Eslam Akl (@eslam3kll) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1139 | The Database Handover | A Dumb Mistake | Critical BUG |
Information disclosure |
NA |
Saransh Saraf (@mr23r0) |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1107 | Baxter SIGMA Spectrum Infusion Pumps: Multiple Vulnerabilities (FIXED) |
Hardcoded credentials
Memory corruption
MiTM
Information disclosure |
Baxter Healthcare |
Deral Heiland (@Percent_X) |
Bug Bounty | 2022-09-08 | 2023-06-13 |