332 | PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 |
RCE
OS command injection
Security code review |
Netgear |
Zion Basque (@mahal0z) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
331 | How I got Owned A Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection |
SQL injection |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
330 | CorePlague: Severe Vulnerabilities in Jenkins Server Lead to RCE |
RCE
XSS
Security code review |
Jenkins |
Ilay Goldman (@GoldmanIlay) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
329 | Self XSS To Stored Through IDOR/ |
IDOR
Self-XSS
Stored XSS |
NA |
Arben Shala (@arbennsh) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
328 | The Silent Spy Among Us: Modern Attacks Against Smart Intercoms |
IoT
OS command injection
Missing authentication
MiTM
SIP |
Akuvox |
Claroty%27s Team82 (@Claroty) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
327 | EJS - Server Side Prototype Pollution gadgets to RCE |
Server-side prototype pollution
RCE
Security code review |
Node.js third-party modules (EJS) |
Mizu (@kevin_mizu) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
326 | Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation) |
Local Privilege Escalation
IoT |
NA |
Sean Pesce (@SeanPesce) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
325 | Wait Time Bypass for fun and Profit |
Rate limiting bypass |
Automattic |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
324 | Clipchamp ( Microsoft Office Product) - Google IAP Authorization bypass allowed access to Internal Environment Leading to Zero Interaction Account takeover |
Authorization bypass
JWT
Account takeover |
Microsoft (ClipChamp) |
Vikas Anil Sharma (@vikzsharma) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
323 | I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection Vulnerability. |
SQL injection
GraphQL |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
322 | Rxss inside href attribute - Bypassing lots of weird checks to takeover accounts! |
Reflected XSS
WAF bypass |
NA |
Ashutosh Dutta (@maniacmarvel_) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
321 | Default Credentials on Sony- Swag Time |
Hardcoded credentials
Information disclosure |
Sony |
Arman (@M7arm4n) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
320 | Improper Authentication in Android App |
Logic flaw
Authentication flaw
HTTP response manipulation |
NA |
oXnoOneXo |
Bug Bounty | 2023-03-10 | 2023-06-13 |
319 | Bugging Out: My Experience of Earning $300 for Reporting an Unexpected Bug |
Subdomain takeover |
NA |
Charlie : The Hacker |
Bug Bounty | 2023-03-10 | 2023-06-13 |
318 | CVE-2022-36413 Unauthorized Reset Password of Zoho ManageEngine ADSelfService Plus |
Password reset
OTP bruteforce
Account takeover
Authentication bypass |
Zoho (ManageEngine) |
Sky |
Bug Bounty | 2023-03-10 | 2023-06-13 |
317 | Account Takeover: An Epic Bug Bounty Story |
Account takeover
Self-XSS
Pre-account takeover |
NA |
Jaydev Ahire |
Bug Bounty | 2023-03-11 | 2023-06-13 |
316 | [Netflix][Smart TV] — Chaining Self-XSS with Session poisoning. |
Self-XSS
Cookie injection
Session management issue |
Netflix |
Lyubomir Tsirkov (@lyubo_tsirkov) |
Bug Bounty | 2023-03-11 | 2023-06-13 |
315 | CCAI |
XSS |
Google |
NDevTK (@ndevtk) |
Bug Bounty | 2023-03-11 | 2023-06-13 |
314 | The story of how I was able to chain SSRF with Command Injection Vulnerability |
SSRF
OS command injection
RCE |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2023-03-12 | 2023-06-13 |
313 | P1 Vulnerability by Bypassing the membership payment page |
Payment bypass |
NA |
Viktor Mares |
Bug Bounty | 2023-03-12 | 2023-06-13 |
312 | Dolibarr : unauthenticated contacts database theft |
SQL injection
Security code review |
Dolibarr |
Vladimir |
Bug Bounty | 2023-03-13 | 2023-06-13 |
311 | How I Leak Other’s Access Token by Exploiting Evil Deeplink Flaw |
Insecure deeplink
Android
Account takeover |
NA |
Crisdeo Nuel Siahaan |
Bug Bounty | 2023-03-13 | 2023-06-13 |
310 | The Time I Hacked Google’s Manual Actions Database |
Broken Access Control
Authorization flaw |
Google |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2023-03-13 | 2023-06-13 |
309 | Veeam Backup and Replication CVE-2023-27532 Deep Dive |
Local Privilege Escalation |
Veeam |
James Horseman (@JamesHorseman2) |
Bug Bounty | 2023-03-13 | 2023-06-13 |
308 | Microsoft Defender for Cloud Management Port Exposure Confusion |
Cloud
Security misconfiguration |
Microsoft |
Aaron Sawitsky |
Bug Bounty | 2023-03-14 | 2023-06-13 |