156 | Methodological approach to find business logic bugs |
Logic flaw
Payment tampering
IP address validation bypass |
NA |
Fady Othman (@Fady_Othman) |
Bug Bounty | 2023-04-25 | 2023-06-13 |
155 | API Misconfiguration - Algolia API Key |
Hardcoded API keys |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
154 | Never Connect to RDP Servers Over Untrusted Networks |
RDP |
Microsoft |
Olivier Bilodeau (@obilodeau) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
153 | Finding XSS in a million websites (cPanel CVE-2023-29489) |
Reflected XSS
Security code review |
cPanel |
Shubham Shah (@infosec_au) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
152 | Git Arbitrary Configuration Injection (CVE-2023-29007) |
Logic flaw
Arbitrary Code Execution
Security code review |
Git |
André Baptista (@0xacb) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
151 | Alias file to rule them all — One click code execution with alias file in macOS |
Arbitrary Code Execution
TCC bypass |
Apple (macOS) |
Mikko Kenttälä (@Turmio_) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
150 | Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587) |
TOCTOU
NULL pointer dereference
Arbitrary file write
Local Privilege Escalation |
Avast |
Denis Skvortcov (@Denis_Skvortcov) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
149 | Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707) |
RCE
Insecure deserialization |
Microsoft (Exchange) |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
148 | Redash SAML Authentication Bypass |
SAML
Authentication bypass |
Redash |
An Trinh (@_tint0) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
147 | Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO |
CSP bypass |
Piwik |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
146 | Privilege Escalation in Microsoft Windows |
Local Privilege Escalation |
Microsoft (Windows) |
Tobias Neitzel (@qtc_de) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
145 | How I Chained an Information Disclosure Bug with SQL Injection |
SQL injection
.git folder disclosure |
NA |
Mba-oji Chiagoziem (@g0ziem) |
Bug Bounty | 2023-04-30 | 2023-06-13 |
144 | Netflix — Bypassing Multi-Factor Authentication (MFA) |
MFA bypass |
Netflix |
Lyubomir Tsirkov (@lyubo_tsirkov) |
Bug Bounty | 2023-04-30 | 2023-06-13 |
143 | Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera |
RCE
Unrestricted file upload
Path traversal
Security code review |
Oracle (Opera) |
Shubham Shah (@infosec_au) |
Bug Bounty | 2023-04-30 | 2023-06-13 |
142 | TENDA–N301-v6–(CVE-2023–29680,CVE-2023–29681) |
Sensitive Information Sent Over an Unencrypted Channel |
Tenda |
Mateus Pantoja |
Bug Bounty | 2023-04-30 | 2023-06-13 |
141 | Bug Bounty Writeup: Stored XSS Vulnerability WAF Bypass |
Stored XSS
WAF bypass |
NA |
Rafael Silva "lopseg" |
Bug Bounty | 2023-05-01 | 2023-06-13 |
140 | Unauthorized access to the admin panel via leaked credentials on the WayBackMachine |
Information disclosure |
NA |
Arman (@M7arm4n) |
Bug Bounty | 2023-05-01 | 2023-06-13 |
139 | Azure Devops CICD Pipelines - Command Injection With Parameters, Variables And A Discussion On Runner Hijacking |
CI/CD
OS command injection
RCE |
Microsoft (Azure DevOps Pipelines) |
Sana Oshika (@bigshika) |
Bug Bounty | 2023-05-01 | 2023-06-13 |
138 | Apache Solr 8.3.1 RCE from exposed administration interface |
RCE
Unrestricted file upload
XSLT injection
Path traversal |
Apache Solr |
Nicolas Brunner |
Bug Bounty | 2023-05-01 | 2023-06-13 |
137 | Placeholder for Dayzzz: Abusing placeholders to extract customer informations |
SSTI
Information disclosure |
GitHub |
Ophion Security (@OphionSecurity) |
Bug Bounty | 2023-05-01 | 2023-06-13 |
136 | AWS Identity Center (formerly known as AWS SSO): A Guide to Privilege Escalation and Identity and Access Management |
Privilege escalation
Cloud |
AWS |
Jason Kao |
Bug Bounty | 2023-05-01 | 2023-06-13 |
135 | SSD Advisory – KerioControl Remote Code Execution |
RCE
TAR path traversal |
GFI Software (KerioControl) |
Simon Janz |
Bug Bounty | 2023-05-02 | 2023-06-13 |
134 | CVE-2023-28231: RCE In The Microsoft Windows DHCPv6 Service |
RCE
Buffer Overflow
Memory corruption |
Microsoft (Windows) |
Guy Lederfein (@glederfein) |
Bug Bounty | 2023-05-02 | 2023-06-13 |
133 | How do I Bypass Payment when a Subscription ends so I don’t have to pay for my subscription |
Payment bypass
Logic flaw |
NA |
Aidil Arief |
Bug Bounty | 2023-05-02 | 2023-06-13 |
132 | Securing Databricks cluster init scripts |
Privilege escalation
Cloud |
Databricks |
Elia Florio |
Bug Bounty | 2023-05-02 | 2023-06-13 |