591 | YAFPC — Unauthenticated Remote Code Execution |
Authentication bypass
Hardcoded credentials
RCE |
NA |
Luke Paris |
Bug Bounty | 2023-01-14 | 2023-06-13 |
590 | XSS using postMessage in Google Cloud Theia notebooks [Google VRP] |
XSS
postMessage |
Google |
Sreeram KL (@kl_sree) |
Bug Bounty | 2023-01-15 | 2023-06-13 |
589 | Critical Vulnerability through OSINT only |
Information disclosure |
NA |
Viktor Mares |
Bug Bounty | 2023-01-15 | 2023-06-13 |
588 | thisclosed_#2 - PostgreSQL Database Exfiltration through the abuse of PostgREST requests |
SQL injection |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2023-01-16 | 2023-06-13 |
587 | Account Take Over Due To AWS Cognito Misconfiguration |
Amazon cognito misconfiguration
Account takeover |
NA |
Deshine |
Bug Bounty | 2023-01-16 | 2023-06-13 |
586 | Full Account Take Over by very simple trick. |
Account takeover
Broken Access Control |
NA |
XeRox01 (@xerox0x1) |
Bug Bounty | 2023-01-16 | 2023-06-13 |
585 | CVE-2022-21587 (Oracle E-Business Suite Unauthenticated RCE) |
RCE
Unrestricted file upload
Zip Slip attack |
Oracle |
@vudq16 |
Bug Bounty | 2023-01-16 | 2023-06-13 |
584 | 2022 Microsoft Teams RCE |
RCE
Insecure deeplink
Webview |
Microsoft |
@adm1nkyj1 |
Bug Bounty | 2023-01-16 | 2023-06-13 |
583 | Unauthenticated Configuration Export in Multiple WAGO Products |
Path traversal
Security code review |
WAGO |
ONEKEY (@onekey_sec) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
582 | AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass |
Cloud
Logic flaw
CloudTrail bypass |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
581 | DOM-Based XSS for fun and profit $$$! | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
580 | How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services |
SSRF
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-01-17 | 2023-06-13 |
579 | Centreon map vulnerability |
Authentication bypass |
Centreon |
Vladimir |
Bug Bounty | 2023-01-17 | 2023-06-13 |
578 | XML Security in Java |
XXE
Billion laugh attack
DoS |
NA |
Pieter De Cremer (@0xDC0DE) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
577 | Security Audit of Git |
Memory corruption
Out-of-bounds Write
Out-of-bounds Read |
Git |
Markus Vervier (@marver) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
576 | From Error_Log File(P4) To Company Account Takeover(P1) and Unauthorized Actions On API |
Information disclosure |
NA |
Muhanad Israiwi (@IsrewyMohand) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
575 | Sudoedit bypass in Sudo <= 1.9.12p1 (CVE-2023-22809) |
Local Privilege Escalation |
Sudo |
Matthieu Barjole (@aevy__) |
Bug Bounty | 2023-01-18 | 2023-06-13 |
574 | How I identified and reported vulnerabilities in Oracle and the rewards of responsible disclosure:From Backup Leak to Hall of Fame |
Information disclosure |
Oracle |
ParagBagul |
Bug Bounty | 2023-01-18 | 2023-06-13 |
573 | The MarkdownTime Vulnerability: How to Avoid This DoS Attack on Business Critical Services |
DoS |
GitLab
GitHub
commonmarker RubyGem |
Tor Beer (@tor19951) |
Bug Bounty | 2023-01-18 | 2023-06-13 |
572 | Nothing new under the Sun – Discovering and exploiting a CDE bug chain |
Printer hacking
Local Privilege Escalation
Memory corruption
Buffer Overflow |
Oracle |
Marco Ivaldi / Raptor (@0xdea) |
Bug Bounty | 2023-01-18 | 2023-06-13 |
571 | Azure Active Directory Flaw Allowed SAML Persistence |
Azure AD
SAML
SSO |
Microsoft (Azure) |
Secureworks Counter Threat Unit (@Secureworks) |
Bug Bounty | 2023-01-18 | 2023-06-13 |
570 | API Misconfiguration - No Swag of SwaggerUI |
Security misconfiguration
Privilege escalation |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
569 | EmojiDeploy: Smile! Your Azure web service just got RCE’d ._. |
RCE
Cloud
CSRF
CORS misconfiguration |
Microsoft (Azure) |
Liv Matan (@terminatorLM) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
568 | The easiest way I used to bypass an admin panel |
HTTP request smuggling
Account takeover |
NA |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
567 | CVE-2022-47966 SAML ShowStopper |
SAML
XSLT injection |
Zoho (ManageEngine) |
Khoa Dinh (@_l0gg) |
Bug Bounty | 2023-01-19 | 2023-06-13 |