1529 | Finding vulnerabilities in Swiss Post%27s future e-voting system - Part 2 |
Insecure deserialization
Cryptographic issues |
NA |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2022-05-22 | 2023-06-13 |
1506 | From open redirect to RCE in one week |
Open redirect
SSRF
Insecure deserialization
LFI
RCE |
Mail.ru |
byq (@ByQwert) |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1434 | Miracle - One Vulnerability To Rule Them All |
Insecure deserialization
SSRF
RCE |
Oracle |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1418 | Bypassing .NET Serialization Binders |
Insecure deserialization
RCE |
Microsoft |
Markus Wulftange (@mwulftange) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1374 | Netwrix Auditor Advisory |
Insecure deserialization |
Netwrix |
Jordan Parkin |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1342 | SSD Advisory – Microsoft SharePoint Server WizardConnectToDataStep4 Deserialization Of Untrusted Data RCE |
Insecure deserialization
RCE |
Microsoft |
Alex Birnberg (@alexbirnberg) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1338 | Riding The Inforail To Exploit Ivanti Avalanche |
RCE
Insecure deserialization
Race condition
Authentication bypass |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1205 | Fishbowl Disclosure: CVE-2022-29805 |
Insecure deserialization |
Fishbowl |
Michael Rand |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1204 | Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets? |
Robotic Process Automation
Insecure deserialization
SQL injection
MiTM |
Blue Prism |
Nimrod Stoler (@n1mr0d5) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1100 | Riding The Inforail To Exploit Ivanti Avalanche Part 2 |
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
994 | CVE-2022-41343 |
RCE
Insecure deserialization
Phar deserialization |
dompdf |
Tanto Security team (@TantoSecurity) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
981 | VMware vCenter Server Platform Services Controller Unsafe Deserialization vulnerability |
Insecure deserialization
Security code review |
VMware |
Marcin %27Icewall%27 Noga (@_Icewall) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
944 | PHP Filters Chain: What Is It And How To Use It |
Insecure deserialization
PHP filter chain |
Laravel |
Rémi Matasse (@_remsio_) |
Bug Bounty | 2022-10-18 | 2023-06-13 |
941 | Remote Code Execution in Melis Platform |
RCE
Path traversal
Insecure deserialization
Security code review |
Melis Platform |
Karim El Ouerghemmi |
Bug Bounty | 2022-10-18 | 2023-06-13 |
910 | Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager |
RCE
Insecure deserialization
Security code review |
VMware |
Sina Kheirkhah (@SinSinology) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
783 | Multiple vulnerabilities in H2O ≤ 3.32.1.3 |
Insecure deserialization
RCE
Arbitrary file read
Security code review |
H2O |
Clément Amic |
Bug Bounty | 2022-11-23 | 2023-06-13 |
673 | From PostAuth RCE to PreAuth RCE on Liferay Portal |
RCE
Insecure deserialization |
NA |
RV Sharma |
Bug Bounty | 2022-12-20 | 2023-06-13 |
551 | CVE from 2018 Strikes Again |
RCE
Insecure deserialization
Thick client |
NA |
Colin McQueen |
Bug Bounty | 2023-01-23 | 2023-06-13 |
521 | Unserializable, But Unreachable: Remote Code Execution On vBulletin |
RCE
Insecure deserialization
Security code review |
vBulletin |
Charles Fol (@cfreal_) |
Bug Bounty | 2023-01-31 | 2023-06-13 |
508 | Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails |
RCE
Security code review
Missing authentication
Insecure deserialization |
IBM |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2023-02-02 | 2023-06-13 |
493 | GoAnywhere MFT - A Forgotten Bug |
Insecure deserialization
Security code review |
Fortra (GoAnywhere) |
Florian Hauser (@frycos) |
Bug Bounty | 2023-02-06 | 2023-06-13 |
479 | Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization |
Insecure deserialization
RCE
Security code review |
Inductive Automation Ignition |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
413 | Unauthenticated RCE in Goanywhere |
Insecure deserialization
RCE
Security code review |
Fortra (GoAnywhere) |
Youssef Muhammad (@yosef0x1) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
378 | CVE-2022-38108: RCE In Solarwinds Network Performance Monitor |
Insecure deserialization
RCE
Security code review |
SolarWinds |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
370 | Introducing Aladdin |
Insecure deserialization |
Microsoft (Windows) |
Lefteris Panos (@lefterispan) |
Bug Bounty | 2023-03-01 | 2023-06-13 |