257 | Attacking Android Antivirus Applications |
Android
Improper Export of Android Application Components |
McAfee |
2Dai (@mabenz68) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
256 | I’d TAP That Pass |
Azure AD
Cloud
OAuth |
NA |
Daniel Heinsen (@hotnops) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
255 | BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained |
Account takeover
Azure AD
Cloud
XSS
Privilege escalation |
Microsoft (Bing) |
Hillai Ben-Sasson (@hillai) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
254 | It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS |
RCE
Stored XSS
Security code review |
LibreNMS |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
253 | Hacking Admin Panel & Getting free subscription |
Exposed registration API
Privilege escalation
Account takeover |
NA |
Zeeshan Mustafa (@by6153) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
252 | CVE-2022-37734: graphql-java Denial-of-Service |
GraphQL
DoS
Security code review |
graphql-java |
Artem Logutov |
Bug Bounty | 2023-03-30 | 2023-06-13 |
251 | Riding the Azure Service Bus (Relay) into Power Platform |
RCE
Cross-tenant vulnerability
Cloud
Insecure deserialization |
Microsoft (Azure) |
Nick Landers (@monoxgas) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
250 | Found SSRF and LFI in Just 10 minutes of using burp! |
SSRF
LFI |
NA |
Khaled Mohamed (@0xElkomy) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
249 | Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack |
RCE
CI/CD
Supply chain attack |
Microsoft (Azure Pipelines) |
Nadav Noy |
Bug Bounty | 2023-03-30 | 2023-06-13 |
248 | Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383) |
RCE
XSS
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-03-30 | 2023-06-13 |
247 | How to avoid the aCropalypse |
Privacy issue
Information disclosure
Android |
Google
Microsoft |
Henrik Brodin |
Bug Bounty | 2023-03-30 | 2023-06-13 |
246 | Exploiting Hibernate Injection in "Order by" Clause (Oracle database) |
HQL injection |
NA |
Mannu Linux (@IndiShell1046) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
245 | From an Innocent api-key to PII data |
Information disclosure
Hardcoded API keys |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
244 | Exposed Docker Registries Server as Critical Reminder on Container Security |
Docker Registry |
NA |
Emad Shawky |
Bug Bounty | 2023-03-31 | 2023-06-13 |
243 | Unveiling the Secrets: My Journey of Hacking Google’s OSS |
CSRF
Self-XSS |
Google |
7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) |
Bug Bounty | 2023-03-31 | 2023-06-13 |
242 | Protected Users: you thought you were safe uh? |
Active Directory
Kerberos
NTLM
Internal pentest |
Microsoft (Windows) |
Aurélien CHALOT (@Defte_) |
Bug Bounty | 2023-03-31 | 2023-06-13 |
241 | Beware of Java%27s String.getBytes |
Hash collision
Cryptographic issues
Security code review |
Swiss E-Voting |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2023-03-31 | 2023-06-13 |
240 | Finding RCE in NodeJS templating engine %27Eta%27 - CVE-2022-25967 |
RCE
Server-side prototype pollution
Security code review |
Eta |
Rayhan Ahmed Niloy (@Rayhan0x01) |
Bug Bounty | 2023-04-01 | 2023-06-13 |
239 | Bug Bounty: como encontrei o bug Unrestricted File Upload |
Unrestricted file upload |
NA |
Paulo Mota |
Bug Bounty | 2023-04-02 | 2023-06-13 |
238 | Let’s Hack Citizens Bank |
XSS |
Citizens Bank |
Arman (@M7arm4n) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
237 | Lenovo database of root user credentials exposed |
.git folder disclosure |
Lenovo |
ASTUTE |
Bug Bounty | 2023-04-03 | 2023-06-13 |
236 | Two Minor Cross-Tenant Vulnerabilities in AWS App Runner |
Cross-tenant vulnerability
Cloud |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
235 | Simple Bugs 0x01: Password Changing to Account Takeover! |
Account takeover
CSRF |
NA |
Vitor Falcao (@egl_falcao) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
234 | Blind XSS via SMS Support Chat — $1100 Bug Bounty! |
Blind XSS
Chatbot |
NA |
Chevon Phillip (@ChevonPhillip) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
233 | CyberGhostVPN - the story of finding MITM, RCE, LPE in the Linux client |
RCE
MiTM
Local Privilege Escalation |
CyberGhost |
mmmds |
Bug Bounty | 2023-04-03 | 2023-06-13 |