207 | SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication (CVE-2023-22620) |
Authentication bypass |
SecurePoint |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
206 | Java Exploitation Restrictions in Modern JDK Times |
Insecure deserialization |
NA |
Florian Hauser (@frycos) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
205 | Losing control over Schneider%27s EcoStruxure Control Expert |
RCE
Path traversal
Security code review |
Schneider Electric |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
204 | How ChatGPT helped me find a bug |
XSS
File upload |
NA |
Abhishekgk |
Bug Bounty | 2023-04-11 | 2023-06-13 |
203 | SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897) |
Memory leak |
SecurePoint |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2023-04-12 | 2023-06-13 |
202 | CVE-2023-29383: Abusing Linux chfn to Misrepresent /etc/passwd |
Local Privilege Escalation |
shadow-utils |
Tom Neaves |
Bug Bounty | 2023-04-12 | 2023-06-13 |
201 | Rooting A Common-criteria Certified Printer To Improve Opsec |
Printer hacking |
Canon |
RedTeam Pentesting (@RedTeamPT) |
Bug Bounty | 2023-04-12 | 2023-06-13 |
200 | TOPdesk vulnerable to XML Signature Wrapping Attacks |
XML Signature Wrapping
SAML
SSO |
TOPdesk |
Paulo A. Silva (@pauloasilva_com) |
Bug Bounty | 2023-04-12 | 2023-06-13 |
199 | How I got RCE in + 10 websites… |
RCE
Security misconfiguration |
NA |
m4cddr (@m4cddr) |
Bug Bounty | 2023-04-13 | 2023-06-13 |
198 | Remote Code Execution Vulnerability in Google They Are Not Willing To Fix |
Dependency confusion
RCE |
Google |
Giraffe Security |
Bug Bounty | 2023-04-14 | 2023-06-13 |
197 | User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264) |
OAuth
OpenID Connect
Privilege escalation
Authentication flaw |
Keycloack |
Jordi Zayuelas i Muñoz |
Bug Bounty | 2023-04-14 | 2023-06-13 |
196 | From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR |
Debug mode enabled
IDOR
Information disclosure
JWT
Broken Access Control
Exposed registration page |
NA |
Aayush Vishnoi (@AayushVishnoi10) |
Bug Bounty | 2023-04-14 | 2023-06-13 |
195 | How do I get cross site scripting(“xss”) in “Nokia” |
XSS |
Nokia |
EL Sayed Mohammed (@ElsayedMo77amed) |
Bug Bounty | 2023-04-16 | 2023-06-13 |
194 | From payload to 300$ bounty: A story of CRLF injection and responsible disclosure on HackerOne |
CRLF injection |
NA |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-16 | 2023-06-13 |
193 | Bypassing the 2FA /MFA — An Easy win |
MFA bypass |
MathWorks |
Shobhit Mehta |
Bug Bounty | 2023-04-16 | 2023-06-13 |
192 | (CVE-2023-2017) Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension |
SSTI
RCE
Security code review |
Shopware |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
191 | A Big company Admin Panel takeover $4500 |
Authentication bypass
40x bypass
Account takeover |
NA |
nanwn |
Bug Bounty | 2023-04-17 | 2023-06-13 |
190 | Multiple Critical Vulnerabilities In Strapi Versions <=4.7.1 |
Authentication bypass
SSTI
RCE
Amazon cognito misconfiguration
Information disclosure |
Strapi |
GhostCcamm (@GhostCcamm) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
189 | Identifying vulnerabilities in GitHub Actions & AWS OIDC Configurations |
CI/CD
OpenID Connect |
AWS |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
188 | [Responsible Disclosure] How we could have deleted any Linkedin post |
IDOR |
LinkedIn |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
187 | Break the Logic: Playing with product ratings on a shopping site(600$) |
Logic flaw
Parameter tampering |
NA |
Fırat |
Bug Bounty | 2023-04-18 | 2023-06-13 |
186 | Impersonating Other Players with UDP Spoofing in Mirror |
Game hacking
UDP spoofing
Reverse engineering |
Unity (Mirror) |
IncludeSec (@IncludeSecurity) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
185 | Popping Tags: Exploiting Template Injections in PRTG Network Monitor |
Reflected XSS
CSTI |
Paessler |
Peter Szot |
Bug Bounty | 2023-04-18 | 2023-06-13 |
184 | My First Case of SSRF Using Dirsearch |
SSRF |
NA |
Mba-oji Chiagoziem (@g0ziem) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
183 | How Material Security Uncovered a Vulnerability in the Gmail API |
Broken Access Control
Authorization flaw |
Google |
Chris Long (@Centurion) |
Bug Bounty | 2023-04-18 | 2023-06-13 |