488 | The Linux Kernel and the Cursed Driver |
Kernel hacking
NULL pointer dereference |
Linux Kernel Organization |
Alon Zahavi (@Alon_Z4) |
Bug Bounty | 2023-02-07 | 2023-06-13 |
487 | Post-Exploitation: Abusing the KeePass Plugin Cache |
Local Privilege escalation
Windows |
KeePass |
Kevin Minacori |
Bug Bounty | 2023-02-07 | 2023-06-13 |
486 | Code Injection via Python Sandbox Escape — how I got a shell inside a network. |
Code injection
RCE |
NA |
Viktor Mares |
Bug Bounty | 2023-02-07 | 2023-06-13 |
485 | [CVE-2023-22855] Kardex MLOG - Insecure path join to RCE via SSTI |
RCE
SSTI
Security code review |
NA |
Patrick Hener (@C1sc01) |
Bug Bounty | 2023-02-07 | 2023-06-13 |
484 | How I Got +1000$ by Clickjacking |
Clickjacking |
NA |
W13DOM |
Bug Bounty | 2023-02-07 | 2023-06-13 |
483 | Bypassing API Restrictions for Fun and Profit |
Payment bypass
Logic flaw |
NA |
Arnav Tripathy |
Bug Bounty | 2023-02-07 | 2023-06-13 |
481 | Reflected XSS on Target with tough WAF ( WAF Bypass ) |
Reflected XSS
WAF bypass |
NA |
Eagle_92 |
Bug Bounty | 2023-02-08 | 2023-06-13 |
480 | Chaining Bugs to get my First Bug Bounty |
CSRF
Open redirect
Clickjacking
Account takeover |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
479 | Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization |
Insecure deserialization
RCE
Security code review |
Inductive Automation Ignition |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
478 | Exploit Development – A Sincere Form of Flattery |
MS-RPC
RCE |
NA |
moth |
Bug Bounty | 2023-02-09 | 2023-06-13 |
477 | Exploits Explained: Default Credentials Still a Problem Today |
Default credentials |
NA |
Popeax |
Bug Bounty | 2023-02-09 | 2023-06-13 |
476 | Azure Ad Kerberos Tickets: Pivoting To The Cloud |
Active Directory
Cloud
Lateral movement |
NA |
Edwin David |
Bug Bounty | 2023-02-09 | 2023-06-13 |
475 | How I got $$$$ Bounty within 5 mins |
RCE
Components with known vulnerabilities |
NA |
Hashir Khan (@P4n7h3Rx) |
Bug Bounty | 2023-02-09 | 2023-06-13 |
474 | Cracking The Odd Case Of Randomness In Java |
Cryptographic issues |
NA |
Joseph (@josep68_) |
Bug Bounty | 2023-02-09 | 2023-06-13 |
472 | Elevation of privileges from Everyone through Avast Sandbox to System AmPPL (CVE-2021-45335, CVE-2021-45336 and CVE-2021-45337) |
Local Privilege Escalation |
Avast |
Denis Skvortcov (@Denis_Skvortcov) |
Bug Bounty | 2023-02-09 | 2023-06-13 |
471 | Information disclosure or GDPR breach? A Google tale… |
Privacy issue
Information disclosure
Missing authentication |
Google |
Luke Berner |
Bug Bounty | 2023-02-10 | 2023-06-13 |
470 | LocalPotato - When Swapping The Context Leads You To SYSTEM |
Windows
NTLM
Local Privilege Escalation |
Microsoft |
Andrea Pierini (@decoder_it) |
Bug Bounty | 2023-02-10 | 2023-06-13 |
469 | Disabling js for the win |
Unrestricted file upload
RCE |
NA |
Vuk Ivanovic |
Bug Bounty | 2023-02-10 | 2023-06-13 |
468 | HubSpot Full Account Takeover in Bug Bounty |
Account takeover
Hyperlink injection
Password reset |
HubSpot |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
467 | We Hacked GitHub for a Month: Here’s What We Found |
Pre-account takeover
Broken Access Control
Email verification bypass
Logic flaw |
GitHub |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
466 | A tale of a full Business Takeover — Red Team Diaries |
MITM
Credential stuffing
Password spraying |
NA |
Dhanesh Dodia - HeyDanny (@Dhanesh_Dodia) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
465 | Vulnerabilities due to XML files processing: XXE in C# applications in theory and in practice |
XXE |
BlogEngine.NET |
Sergey Vasiliev (@_SergVasiliev_) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
464 | IDOR Leads to MASS Account Takeover |
IDOR
Account takeover |
NA |
Yaseen Zubair |
Bug Bounty | 2023-02-12 | 2023-06-13 |
463 | XXE with Auto-Update in install4j |
XXE
Security code review |
Prosys OPC |
Florian Hauser (@frycos) |
Bug Bounty | 2023-02-12 | 2023-06-13 |
462 | SSRF That Allowed Us to Access Whole Infra Web Services and Many More |
SSRF |
NA |
Basavaraj Banakar (@basu_banakar) |
Bug Bounty | 2023-02-12 | 2023-06-13 |