1683 | Unauthenticated Remote Code Execution in Cisco Nexus Dashboard Fabric Controller (formerly DCNM) |
Insecure deserialization
Local Privilege Escalation
RCE |
Cisco |
Pedro Ribeiro (@pedrib1337) |
Bug Bounty | 2022-03-30 | 2023-06-13 |
1682 | CVE-2022-27643 - NETGEAR R6700v3 upnpd Buffer Overflow Remote Code Execution Vulnerability |
Memory corruption
RCE |
Netgear |
Relyze (@relyze) |
Bug Bounty | 2022-03-31 | 2023-06-13 |
1678 | A Large-scale and Longitudinal Measurement Study of DKIM Deployment |
Email spoofing
Phishing |
Google
Mailchimp
Sendgrid
Salesforce |
Chuhan Wang |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1677 | Pwning a Cisco RV340 with a 4 bug chain exploit |
Local Privilege Escalation
OS command injection
RCE
Session management issue |
Cisco |
Liv (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1648 | Meta%27s SparkAR RCE Via ZIP Path Traversal |
RCE
Path traversal |
Meta / Facebook |
Fady Othman (@Fady_Othman) |
Bug Bounty | 2022-04-07 | 2023-06-13 |
1603 | Adventures Into The MeowCorp Bug Bounty Program |
Information disclosure
Weak credentials
SSRF
.git folder disclosure
RCE |
NA |
Nirmal Thapa (@tnirmalz) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1600 | EJS, Server side template injection RCE (CVE-2022-29078) - writeup |
SSTI
RCE |
ejs
NetApp |
Eslam Salem (@net_code) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1582 | Hacking a Bank by Finding a 0day in DotCMS |
Directory traversal
Unrestricted file upload
RCE |
NA |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-05-03 | 2023-06-13 |
1581 | [UNPATCHED] Cli: gh run download implementation allows overwriting git repository configuration upon artifacts downloading |
RCE |
GitHub |
Vladimir Metnew (@vladimir_metnew) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1571 | Cloudflare Pages, part 1: The fellowship of the secret |
Command injection
Container escape
Bash Path injection
RCE
Local Privilege Escalation
Information disclosure |
Cloudflare |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1566 | Can analyzing javascript files lead to remote code execution? |
Unrestricted file upload
RCE |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2022-05-08 | 2023-06-13 |
1564 | RCE via Dependency Confusion |
Dependency confusion |
NA |
Samrat Gupta (@Sm4rty_) |
Bug Bounty | 2022-05-10 | 2023-06-13 |
1557 | New Wine in Old Bottle - Microsoft Sharepoint Post-Auth Deserialization RCE (CVE-2022-29108) |
Insecure deserialization
RCE |
Microsoft |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2022-05-12 | 2023-06-13 |
1539 | Research: Auditing WordPress Plugins |
SQL injection
LFI
XSS
RCE |
NA |
cy//ective (@cyllective) |
Bug Bounty | 2022-05-20 | 2023-06-13 |
1520 | 2nd RCE and XSS in Apache Struts before 2.5.30 |
RCE
Double OGNL evaluation
XSS |
Apache Struts |
Chris (@mc_0wn) |
Bug Bounty | 2022-05-25 | 2023-06-13 |
1516 | Bygone Vulnerabilities - Remote Code Execution in IBM Lotus SameTime Clients (CVE-2013-0553) |
XSS
RCE |
IBM |
Brian (@hoyahaxa) |
Bug Bounty | 2022-05-27 | 2023-06-13 |
1515 | A Simple SQL Injection in an Air Force Website |
SQL injection |
U.S. Dept Of Defense |
Corben Leo (@hacker_) |
Bug Bounty | 2022-05-27 | 2023-06-13 |
1506 | From open redirect to RCE in one week |
Open redirect
SSRF
Insecure deserialization
LFI
RCE |
Mail.ru |
byq (@ByQwert) |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1505 | SQL injection to Remote Command Execution (RCE) |
SQL injection
RCE |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1503 | Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty |
RCE |
Microsoft |
Chen Cohen (@chencococococo) |
Bug Bounty | 2022-06-01 | 2023-06-13 |
1498 | Ivanti EPM Remote Code Execution |
RCE
Components with known vulnerabilities |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-06-05 | 2023-06-13 |
1485 | CVE-2022-1040 Sophos XG Firewall Authentication bypass |
Authentication bypass
RCE |
Sophos |
Nguyễn Đình Biển (@biennd279) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1470 | SynLapse – Technical Details for Critical Azure Synapse Vulnerability |
Cross-tenant vulnerability
RCE
Cloud |
Microsoft |
Tzah Pahima (@TzahPahima) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1469 | Cryptographic Side-Channels (Timing Leaks) in JSBN |
Cryptographic issues
Side-channel attack
Timing attack |
Xfinity Opensource |
Soatok (@SoatokDhole) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1468 | 403 bypass on a fortune 100 financial institution (P3) |
Information disclosure
Authorization flaw
Forced browsing |
NA |
Damaidec |
Bug Bounty | 2022-06-14 | 2023-06-13 |