436 | Readline crime: exploiting a SUID logic bug |
Local Privilege Escalation |
Arch Linux
util-linux |
roddux |
Bug Bounty | 2023-02-16 | 2023-06-13 |
435 | Hacking the Search Bar: The Story of Discovering and Reporting an XSS Vulnerability on Bing.com |
XSS |
Microsoft (Bing) |
Niraj Mahajan |
Bug Bounty | 2023-02-18 | 2023-06-13 |
434 | Found an URL in the android application source code which lead to an IDOR |
Android
Information disclosure
IDOR |
NA |
Vengeance |
Bug Bounty | 2023-02-18 | 2023-06-13 |
433 | Disabling ClamAV as an Unprivileged User |
Local Privilege Escalation |
ClamAV |
Arch Cloud Labs (@DLL_Cool_J) |
Bug Bounty | 2023-02-19 | 2023-06-13 |
432 | [1500$ Worth — Slack] vulnerability, bypass invite accept process |
Broken Access Control
Logic flaw |
Slack |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-02-20 | 2023-06-13 |
431 | Reflected Cross Site Scripting (Awards 3500$ bounty) |
Reflected XSS |
Shopify |
ShuttlerTech |
Bug Bounty | 2023-02-20 | 2023-06-13 |
430 | Exposing 185M+ Indians’ Personal Information and much more |
Broken Access Control
IDOR
Information disclosure |
Aadhaar
CERT-In |
Robin Justin (@_robinjustin_) |
Bug Bounty | 2023-02-20 | 2023-06-13 |
429 | Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover |
Account takeover
SSO
OTP
Authentication bypass |
NA |
Aidil Arief |
Bug Bounty | 2023-02-20 | 2023-06-13 |
428 | Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header |
WAF bypass
CRLF injection
XSS |
Akamai |
Adam Crosser |
Bug Bounty | 2023-02-21 | 2023-06-13 |
427 | Escaping misconfigured VSCode extensions |
Path traversal
DNS rebinding
XSS
HTML injection
Webview
CSP bypass |
Microsoft (SARIF viewer & Live Preview) |
Vasco Franco |
Bug Bounty | 2023-02-21 | 2023-06-13 |
426 | Reflected Cross site scripting on reddit website (bounty awards $5000) |
Reflected XSS |
Reddit |
ShuttlerTech |
Bug Bounty | 2023-02-21 | 2023-06-13 |
425 | Multiple vulnerabilities in Nokia BTS Airscale ASIKA |
Base transceiver station
Path traversal
Hardcoded private key
Local Privilege Escalation
Security misconfiguration |
Nokia |
Geoffrey Bertoli (@YofBalibump) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
424 | ClamAV Critical Patch Review |
RCE
Memory corruption
Buffer Overflow
XXE
Security code review |
ClamAV |
ONEKEY (@onekey_sec) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
423 | What the Vuln: Zimbra |
Zip Slip attack
Path traversal |
NA |
Carlos Yanez |
Bug Bounty | 2023-02-21 | 2023-06-13 |
422 | Trellix Advanced Research Center Discovers a New Privilege Escalation Bug Class on macOS and iOS |
Local Privilege Escalation |
Apple (macOS) |
Austin Emmitt (@alkalinesec) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
421 | Multiple vulnerabilities in Dell Unisphere for PowerMax vApp, VASA Provider vApp and Solutions Enabler vApp CVE-2022-45103 / CVE-2022-45104 |
Parameter injection
Arbitrary file read
RCE |
Dell |
Antoine Carrincazeaux |
Bug Bounty | 2023-02-21 | 2023-06-13 |
420 | Exploiting an HTML injection with dangling markup |
HTML injection
Dangling Markup Injection |
NA |
Yoan Montoya |
Bug Bounty | 2023-02-21 | 2023-06-13 |
419 | Taking over “Google Cloud Shell” by utilizing capabilities and Kubelet |
Container escape
RCE
Kubernetes |
NA |
Chen Shiri (@ChenShiri73) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
416 | With a single request, you can kill any Gitea server |
Application-level DoS |
Gitea |
Khaled Nassar (@knassar702) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
415 | Exploiting Parameter Pollution in Golang Web Apps |
Authorization flaw
HTTP parameter pollution |
Concourse
VMware |
Rick Ramgattie (@RRamgattie) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
414 | Vulnerability write-up - "Dangerous assumptions" |
Prototype pollution
SQL injection
Security code review |
DIVD |
Thomas Rinsma (@thomasrinsma) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
413 | Unauthenticated RCE in Goanywhere |
Insecure deserialization
RCE
Security code review |
Fortra (GoAnywhere) |
Youssef Muhammad (@yosef0x1) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
412 | Insufficient GraphQL API vulnerability due to lack of validation of Authorization Bearer token |
GraphQL
IDOR |
NA |
Int (@intlulz) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
411 | How I got into Nokia HOF in 5 Mins |
Information disclosure |
Nokia |
Abdelrhman Allam (@sl4x0) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
410 | Decoding BlazorPack |
Websockets |
NA |
Rogan Dawes (@RoganDawes) |
Bug Bounty | 2023-02-22 | 2023-06-13 |