1809 | Advisory: Cisco RV340 Dual WAN Gigabit VPN Router (RCE over LAN) |
RCE
Unrestricted file upload
OS command injection |
Cisco |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-17 | 2023-06-13 |
1804 | RCE in GitHub Desktop < 2.9.4 |
RCE |
GitHub |
Vladimir Metnew (@vladimir_metnew) |
Bug Bounty | 2022-02-18 | 2023-06-13 |
1789 | Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing |
Android
Bruteforce
Authentication bypass |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-22 | 2023-06-13 |
1788 | CVE-2021-45467: CWP CentOS Web Panel – preauth RCE |
RCE
LFI
Arbitrary file write |
Centos Web Panel (CWP) |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-01-22 | 2023-06-13 |
1781 | Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager |
Authentication bypass
RCE
SSRF
Path traversal |
VMware |
Egor Dimitrenko (@elk0kc) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1779 | CVE-2022-22947: SpEL Casting And Evil Beans |
RCE
Java Beans |
NA |
Wyatt Dahlenburg (@wdahlenb) |
Bug Bounty | 2022-02-26 | 2023-06-13 |
1777 | BrokenPrint: A Netgear stack overflow |
Memory corruption
RCE |
Netgear |
Alex Plaskett (@alexjplaskett) |
Bug Bounty | 2022-02-28 | 2023-06-13 |
1776 | Pwning a Server using Markdown |
LFI
RCE |
Hashnode |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2022-02-28 | 2023-06-13 |
1757 | Log4shell in google $1337.00 |
Log4shell
RCE |
Google |
amnotacat (@Amnotacat1) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1755 | Oracle Access Manager Pre-Auth RCE (CVE-2021–35587 Analysis) |
RCE |
Oracle |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1754 | SSD Advisory – NETGEAR DGND3700v2 PreAuth Root Access |
Authentication bypass
OS command injection
RCE |
Netgear |
- |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1740 | How I bypassed disable_functions in php to get a remote shell |
RCE |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2022-03-13 | 2023-06-13 |
1735 | Achieving Remote Code Execution via Unrestricted File Upload |
Unrestricted file upload
RCE |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1727 | Securing Developer Tools: Git Integrations |
Local Privilege Escalation |
Microsoft
JetBrains
GitHub |
Sonar (@SonarSource) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1724 | Git honours embedded bare repos, and exploitation via core.fsmonitor in a directory%27s .git/config affects IDEs, shell prompts and Git pillagers |
RCE |
GitHub
Microsoft
JetBrains |
Justin Steven (@justinsteven) |
Bug Bounty | 2022-03-16 | 2023-06-13 |
1723 | From XSS to RCE (dompdf 0day) |
XSS
RCE |
NA |
Positive Security (@positive_sec) |
Bug Bounty | 2022-03-16 | 2023-06-13 |
1708 | iTop – Template Injection inside customer Portal |
SSTI
RCE |
Combodo (iTop) |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2022-03-21 | 2023-06-13 |
1705 | Basic recon to RCE II |
RCE |
NA |
Joshua Martinelle (@J0_mart) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1701 | Remote Code Execution on Western Digital PR4100 NAS (CVE-2022-23121) |
RCE |
Western Digital |
Alex Plaskett (@alexjplaskett) |
Bug Bounty | 2022-03-23 | 2023-06-13 |
1699 | Pwn2Own Austin 2021 : Defeating The Netgear R6700V3 |
RCE
Memory corruption |
Netgear |
Antide Petit (@xarkes_) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1698 | Finding bugs to trigger Unauthenticated Command Injection in a NETGEAR router (PSV-2022–0044) |
XSS
Arbitrary file read
Authentication bypass
OS command injection
RCE |
Netgear |
stypr (@stereotype32) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1691 | Pwning Microsoft Azure Defender for IoT | Multiple Flaws Allow Remote Code Execution for All |
RCE
Memory corruption
SQL injection |
Microsoft |
Kasif Dekel (@kasifdekel) |
Bug Bounty | 2022-03-28 | 2023-06-13 |
1690 | Ruby Deserialization - Gadget on Rails |
Insecure deserialization
RCE |
Ruby on Rails |
HTTPVoid (@httpvoid0x2f) |
Bug Bounty | 2022-03-28 | 2023-06-13 |
1689 | Your NAS is not your NAS ! |
RCE
Memory corruption
Buffer Overflow |
Synology |
Angelboy (@scwuaptx) |
Bug Bounty | 2022-03-28 | 2023-06-13 |
1686 | Joomla! <= 4.1.0 (Tar.php) Zip Slip Vulnerability |
Zip Slip attack
Path traversal
Source code disclosure |
Joomla! |
Egidio Romano / EgiX |
Bug Bounty | 2022-03-29 | 2023-06-13 |