566 | CVE-2022-35690: Unauthenticated RCE In Adobe ColdFusion |
RCE |
Adobe |
rgod |
Bug Bounty | 2023-01-19 | 2023-06-13 |
565 | AWS Cognito pitfalls: Default settings attackers love (and you should know about) |
Amazon cognito misconfiguration |
NA |
Lorenzo Vogelsang (@ptrac3) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
564 | Two Factor Authentication Bypass On Facebook |
MFA bypass |
Meta / Facebook |
Gtm Mänôz (@Gtm0x01) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
563 | Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434) |
Android
Insecure intent
Insecure deeplink
URL validation bypass |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
562 | Bypassing E2E encryption leads to multiple high vulnerabilities. |
IDOR
SSRF |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
561 | CSRF + Stored XSS Leading to Full Account Takeover |
Stored XSS
CSRF
Account takeover |
NA |
Fares Walid (@SirBagoza) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
560 | Vulnerabilities in ManageEngine ADSelfService Plus 6.1 build 6117 |
RCE
OS command injection
Broken Access Control |
Zoho (ManageEngine) |
Antoine Cervoise (@acervoise) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
559 | Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP” |
Kernel hacking
Windows
RCE
Memory corruption
Buffer Overflow |
Microsoft (Windows) |
Valentina Palmiotti (@chompie1337) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
558 | Bypassing Cloudflare WAF: XSS via SQL Injection |
Reflected XSS
SQL injection
WAF bypass |
NA |
Uku Sõrmus |
Bug Bounty | 2023-01-21 | 2023-06-13 |
557 | How I found XSS on Admin Page without login! |
Reflected XSS |
NA |
Abdelrhman Allam (@sl4x0) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
556 | Reflected XSS Leads to 3,000$ Bug Bounty Rewards from Microsoft Forms |
Reflected XSS |
Microsoft |
Supakiad S. (@Supakiad_Mee) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
555 | How i was able to get critical bug on google by get full access on [Google Cloud BI Hackathon] |
Information disclosure |
Google |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
554 | CVE-2023-24068 && CVE-2023-24069: Abusing Signal Desktop Client for fun and for Espionage |
Thick client
Insecure data storage
Local Privilege Escalation |
Signal |
John Jackson (@johnjhacking) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
553 | How i Hacked Scopely with “Sign in with Google” |
Account takeover
CORS misconfiguration
Client-side enforcement of server-side security
OAuth |
Scopely |
Ph.Hitachi |
Bug Bounty | 2023-01-23 | 2023-06-13 |
552 | Activation Context Cache Poisoning: Exploiting CSRSS For Privilege Escalation |
Local Privilege Escalation
Windows |
Microsoft |
Simon Zuckerbraun |
Bug Bounty | 2023-01-23 | 2023-06-13 |
551 | CVE from 2018 Strikes Again |
RCE
Insecure deserialization
Thick client |
NA |
Colin McQueen |
Bug Bounty | 2023-01-23 | 2023-06-13 |
550 | CrossTalk and Secret Agent: Two Attack Vectors on Okta%27s Identity Suite |
Insecure storage of sensitive information
Phishing |
Okta |
Tal Peleg |
Bug Bounty | 2023-01-23 | 2023-06-13 |
549 | Using 0days to Protect the United Nations |
RCE
Authentication bypass
Path traversal |
United Nations |
Florian Hauser (@frycos) |
Bug Bounty | 2023-01-24 | 2023-06-13 |
548 | Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI |
RCE
Authentication bypass
Security code review
JWT |
Yellowfin BI |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2023-01-24 | 2023-06-13 |
547 | Jumping into SOCKS |
Lateral movement |
NA |
Jacques Coertze (@JCoertze) |
Bug Bounty | 2023-01-24 | 2023-06-13 |
546 | Unleashing the power of CSS injection: The access key to an internal API |
CSS injection |
NA |
Sander Wind (@SanderWind) |
Bug Bounty | 2023-01-24 | 2023-06-13 |
545 | Easy 2000$ Race Condition |
Race condition |
NA |
Deshine |
Bug Bounty | 2023-01-25 | 2023-06-13 |
544 | MyBB <= 1.8.31: Remote Code Execution Chain |
RCE
SQL injection
Stored XSS |
MyBB |
Aleksey Solovev |
Bug Bounty | 2023-01-25 | 2023-06-13 |
543 | Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI |
Windows
Cryptographic issues |
Microsoft |
Tomer Peled |
Bug Bounty | 2023-01-25 | 2023-06-13 |
542 | Kamailio’s exec module considered harmful |
OS command injection
SIP |
Kamailio |
Ali Norouzi |
Bug Bounty | 2023-01-26 | 2023-06-13 |