1103 | How I was able to see likes count even though is hidden by victim | YouTube |
Information disclosure
Logic flaw |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1093 | Contentful Access Token Disclosure in Android APK |
Information disclosure
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-12 | 2023-06-13 |
1081 | How I abused the file upload function to get a high severity vulnerability in Bug Bounty |
Unrestricted file upload
Information disclosure |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1069 | Bug Bounty { How I found an Sensitive Information Disclosure( Reconnaissance ) } |
Information disclosure |
NA |
S Rahul (@7srambo) |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1068 | Turning Your Computer Into a GPS Tracker With Apple Maps |
Privacy issue
Information disclosure |
Apple |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1067 | Android Application Forgot Password Token Leakage Leading to Account Takeover |
Information disclosure
Password reset
Account takeover
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-19 | 2023-06-13 |
1037 | Blind XSS on Admin Portal Leads to Information Disclosure |
Blind XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1029 | “Hey Siri, follow that car!” - How traffic cameras expose your location through parking apps. |
Information disclosure
Session hijacking |
NA |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2022-09-26 | 2023-06-13 |
1009 | Tale of Easy P1 Bugs in Wild |
Forced browsing
403 bypass
Information disclosure |
NA |
Harsh Tandel |
Bug Bounty | 2022-10-01 | 2023-06-13 |
1004 | My First And Second Bugs Are — 2FA Bypass |
MFA bypass
HTTP response manipulation
Information disclosure |
NA |
Jai Niresh J |
Bug Bounty | 2022-10-03 | 2023-06-13 |
1000 | How I Found A P1 Bug |
Authentication bypass
Information disclosure |
NA |
Amith |
Bug Bounty | 2022-10-05 | 2023-06-13 |
990 | Full Company Building Takeover |
Information disclosure |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
985 | The easiest bug to get a Hall of fame from a Billion dollar company. |
GraphQL
Information disclosure |
GeHealthcare |
Ravaan |
Bug Bounty | 2022-10-10 | 2023-06-13 |
939 | Vulnerabilities in Tenda%27s W15Ev2 AC1200 Router |
OS command injection
Buffer Overflow
Memory corruption
Stored XSS
Authorization flaw
Information disclosure |
Tenda |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
920 | How I Found Three Credentials Leak on One Google Dork on Bugcrowd program |
Information disclosure |
Cengage |
Ittipatjitrada (@IttipatJitrada) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
918 | Finding Multiple Security Issues on Agorapulse |
Log4shell
RCE
Information disclosure
Broken Access Control
Privilege escalation |
Agorapulse |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
906 | GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown |
OS command injection
Arbitrary file read
Information disclosure
Account takeover
Stored XSS
Lack of rate limiting
Weak credentials
Password policy bypass |
GL.iNet |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
897 | Misconfigured AWS S3 Bucket (Information Disclosure & Subdomain Takeover) |
AWS misconfiguration |
NA |
Gokhan Guzelkokar (@gkhck_) |
Bug Bounty | 2022-10-27 | 2023-06-13 |
885 | 2FA Bypass due to information disclosure & Improper access control. |
DoS
MFA bypass |
NA |
Akash Hamal (@AkashHamal0x01) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
880 | urlscan.io%27s SOAR spot: Chatty security tools leaking private data |
Information disclosure |
NA |
Fabian Bräunlein |
Bug Bounty | 2022-11-01 | 2023-06-13 |
878 | How I Get 5x Swag From Sony |
DOM XSS
Directory listing
Default credentials
Information disclosure |
Sony |
Naeem Ahmed Sayed (@0xNaeem) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
868 | Case of Admin Bypass for RCE, XSS, and Information Disclosure |
RCE
Unrestricted file upload
Stored XSS
Information disclosure |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
818 | Information Exposure — My Fourth Finding on Hackerone! |
Directory listing
Information disclosure |
NA |
mehedishakeel (@mehedishakeel) |
Bug Bounty | 2022-11-17 | 2023-06-13 |
792 | CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You |
RCE
DNS rebinding
Information disclosure |
Tailscale |
Jamie McClymont (@JJJollyjim) |
Bug Bounty | 2022-11-22 | 2023-06-13 |
762 | Improper error handling leads to exposing internal tokens |
Information disclosure |
NA |
Agnieszka Pietruczuk |
Bug Bounty | 2022-11-28 | 2023-06-13 |