232 | Holiday Hunting With Aquatone |
SSRF
Missing authentication
Information disclosure |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
231 | Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server |
RCE
SSTI
Authorization bypass
Groovy scripting |
Hitachi Vantara (Pentaho) |
Harry Withington |
Bug Bounty | 2023-04-04 | 2023-06-13 |
230 | Bypassing Amazon Kids+ Parental Controls |
Logic flaw |
Amazon |
n00py (@n00py1) |
Bug Bounty | 2023-04-04 | 2023-06-13 |
229 | Post Account Takeover? Account Takeover of Internal Tesla Accounts |
Account takeover
SSO |
Tesla |
Evan Connelly (@Evan_Connelly) |
Bug Bounty | 2023-04-04 | 2023-06-13 |
228 | Windows Task Scheduler Application, Version 19044.1706 Advisory |
Unquoted search path
Local Privilege Escalation |
Microsoft (Windows) |
Ben Lincoln (@0x00C651E0) |
Bug Bounty | 2023-04-04 | 2023-06-13 |
227 | Microsoft Intune, Version 1.55.48.0 Advisory |
Unquoted search path
Local Privilege Escalation |
Microsoft (Intune) |
Ben Lincoln (@0x00C651E0) |
Bug Bounty | 2023-04-04 | 2023-06-13 |
226 | Discovering Headroll (CVE-2023–0704) in Chromium |
SOP bypass
Browser hacking |
Google (Chromium) |
Rhys Elsmore (@rhyselsmore) |
Bug Bounty | 2023-04-05 | 2023-06-13 |
225 | Exploiting insecure exception logging |
Blind XSS |
NA |
Bogdan Calin |
Bug Bounty | 2023-04-05 | 2023-06-13 |
224 | Bash Privileged-mode Vulnerabilities In Parallels Desktop And CDPATH Handling In MacOS |
MacoS
Local Privilege Escalation |
Parallels |
Reno Robert (@renorobertr) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
223 | Simple Bugs 0x02: Overwritting Uploaded Files |
Normalization |
NA |
Vitor Falcao (@egl_falcao) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
222 | Let me Unmask my next 👻 |
IDOR
Payment bypass |
Tinder |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
221 | Escaping Adobe Sandbox: Exploiting an Integer Overflow in Microsoft Windows Crypto Provider |
Integer overflow
Memory corruption |
Microsoft |
Michele Campa (@s1ckb017) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
220 | A web security story from 2008: silently securing JSON.parse |
Parsing issue
XSS
Arbitrary Code Execution |
JSON.parse |
Mike Samuel (@mvsamuel) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
219 | SharePoint Webpart Property Traversal Vulnerability Analysis (CVE-2022–38053, CVE-2023–21742, CVE-2023–21717) |
Property traversal |
Microsoft (Sharepoint) |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
218 | Stored Cross-Site Scripting (XSS) in Zimbra version 8.8.15_GA_4059 CVE-2022-41348 |
Stored XSS |
Zimbra |
Guillaume Jacques |
Bug Bounty | 2023-04-07 | 2023-06-13 |
217 | SQL Wildcard DoS - Hang Till Death |
DoS
File upload |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-04-08 | 2023-06-13 |
216 | Steal authentication token with one-click on misconfigured WebView. |
Android
Webview
Account takeover |
NA |
Kerolos A. Saber (@0xWise) |
Bug Bounty | 2023-04-08 | 2023-06-13 |
215 | How I was able to change password of any corporate user |
Account takeover
Password reset
Authentication bypass |
NA |
CH3TAN |
Bug Bounty | 2023-04-09 | 2023-06-13 |
214 | A successful prototype pollution chained to a DOM XSS |
Prototype pollution
DOM XSS |
NA |
Allam Rachid (@blank_cold) |
Bug Bounty | 2023-04-10 | 2023-06-13 |
213 | Account Take Over (Via an API) |
Account takeover
Information disclosure
Broken Access Control
Cryptographic issues |
NA |
Thabiso Mokoena |
Bug Bounty | 2023-04-10 | 2023-06-13 |
212 | Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories |
Repojacking
Supply chain attack |
NA |
Joren Vrancken |
Bug Bounty | 2023-04-10 | 2023-06-13 |
211 | CVE-2023-1767 - Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score |
Stored XSS
Markdown XSS
Supply chain attack |
Snyk |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2023-04-10 | 2023-06-13 |
210 | From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys |
Cloud
Privilege escalation |
Microsoft (Azure) |
Roi Nisimi (@) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
209 | Shell in the Ghost: Ghostscript CVE-2023-28879 writeup |
Buffer Overflow
Memory corruption
RCE |
Ghostscript |
sigabrt9 (@sigabrt9) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
208 | Pretalx Vulnerabilities: How to get accepted at every conference |
Arbitrary file read
Arbitrary file write
RCE
Security code review |
Pretalx |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-04-11 | 2023-06-13 |