2670 | This Man Thought Opening A TXT File Is Fine, He Thought Wrong. MacOS CVE-2019-8761 |
MacOS
HTML injection |
Apple |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2623 | Playing With iframes: Bypassing Content-Security-Policy |
CSP bypass
Open redirect
HTML injection |
NA |
JM Sanchez / 0xEchidonut (@jmrcsnchz) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2579 | Injecting Punycode URL Within the Arbitrary Text via Comment Box In Google Photo Sharing Option |
HTML injection |
Google |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2021-05-05 | 2023-06-13 |
2544 | DOS & Stored HTML Injection Bug Bounty Writeup |
DoS
HTML injection |
NA |
RiotSecurityTeam (@RiotSecTeam) |
Bug Bounty | 2021-05-19 | 2023-06-13 |
2470 | HTML Injection and a dream in Google Chrome for Linux (Write Up) |
HTML injection |
Google |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-06-17 | 2023-06-13 |
2430 | Exploiting Auto-save Functionality To Steal Login Credentials |
HTML injection |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2021-07-06 | 2023-06-13 |
2331 | Taking Over Employee Accounts by Managers with Zero Employee Interaction |
HTML injection |
NA |
Chaitanya Rajhans (@Chaitanya_024) |
Bug Bounty | 2021-08-12 | 2023-06-13 |
2324 | Simple HTML Injection to $250 |
Account takeover
Mass assignment |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2280 | What would you do if Oracle’s mailing server sent you this? |
HTML injection |
Oracle |
I am Broot |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2174 | A short story of Content Spoofing to HTML Injection in Apple using Dangling Markup Injection |
HTML injection
Dangling Markup Injection |
Apple |
Rishu Ranjan (@tweetit_rrj) |
Bug Bounty | 2021-10-03 | 2023-06-13 |
2086 | From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy |
Broken Access Control
Information disclosure
IDOR
HTML injection |
Udemy |
Mostafa Mamdoh |
Bug Bounty | 2021-11-12 | 2023-06-13 |
1921 | Xiaomi Execute Arbitrary JavaScript |
XSS
HTML injection
Android |
Xiaomi |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-01-13 | 2023-06-13 |
1780 | SSRF & LFI In Uploads Feature |
SSRF
LFI
HTML injection |
NA |
Raymond Lind |
Bug Bounty | 2022-02-26 | 2023-06-13 |
1739 | Party time: Injecting code into Teleparty extension |
HTML injection
Open redirect
Browser extension hacking |
Teleparty |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-03-14 | 2023-06-13 |
1644 | XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain |
XSS
HTML injection |
Huawei |
Ahmed Hassan |
Bug Bounty | 2022-04-10 | 2023-06-13 |
1640 | SVG SSRFs and saga of bypasses |
SSRF
HTML injection |
NA |
Preetham Bomma (@cyber01_) |
Bug Bounty | 2022-04-11 | 2023-06-13 |
1494 | Security Vulnerability in GitLab: Sending Arbitrary Requests through Jupyter Notebooks |
HTML injection |
GitLab |
Daniel Fürst (@DnlFrst) |
Bug Bounty | 2022-06-07 | 2023-06-13 |
1489 | De-Anonymization attacks against Proton services |
Privacy issue
Information disclosure
HTML injection
Local Privilege Escalation |
Proton AG |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1423 | HTML and Hyperlink Injection via Share Option In Microsoft Onenote Application |
HTML injection
Phishing |
Microsoft |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1389 | stored XSS and stored HTML Injection in United Nations Website |
XSS
HTML injection |
United Nations |
Ahmed Hassan |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1370 | Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP |
XSS
CSP bypass
HTML injection |
Microsoft |
Numan Turle (@numanturle) |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1292 | How I Earned €150 in 2 Minutes | HTML injection in email |
HTML injection |
NA |
Thillai Raj |
Bug Bounty | 2022-07-30 | 2023-06-13 |
1266 | Bypassed Cloudflare’s Web Application Firewall (WAF) |
XSS
HTML injection
WAF bypass |
NA |
Ansh Vaid (@anshvaid4) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1151 | HTMLI/XSS - Crafting a better PoC |
XSS
HTML injection |
NA |
RiotSecurityTeam (@RiotSecTeam) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1021 | The forgotten IPFS vulnerabilities |
Web3 hacking
Path traversal
CORS misconfiguration
HTML injection |
Filecoin Security |
tintinweb |
Bug Bounty | 2022-09-28 | 2023-06-13 |