3116 | Watch your requests! Open redirect to a complete account takeover |
Path traversal
Open redirect
SSRF
Account takeover |
NA |
Suraj Disoja (@ninetyn1ne_) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3087 | GitHub Pages - Multiple RCEs via insecure Kramdown configuration - $25,000 Bounty |
RCE
Path traversal |
GitHub |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2020-10-20 | 2023-06-13 |
3048 | Silver Peak Unity Orchestrator RCE |
RCE
Authentication bypass
Path traversal
SQL injection |
Silver Peak |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-08 | 2023-06-13 |
3030 | SD-PWN Part 2 — Citrix SD-WAN Center — Another Network Takeover |
RCE
Authentication bypass
Path traversal
OS command injection
Local Privilege Escalation |
Citrix Systems |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3007 | SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover |
RCE
SSRF
Arbitrary file write
Path traversal
OS command injection
Local Privilege Escalation |
Cisco |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
3004 | SD-PWN Part 4 — VMware VeloCloud — The Last Takeover |
RCE
Authentication bypass
Default credentials
SQL injection
Path traversal
LFI |
VMware |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
2918 | $10,000 for a vulnerability that doesn’t exist |
Path traversal |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2661 | Intro to Open-source Bug Bounty |
Path traversal |
Mailtrain |
Arjun Shibu (@0xsegf) |
Bug Bounty | 2021-04-05 | 2023-06-13 |
2546 | Path Traversal in MobileSafari |
Path traversal |
Apple |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-05-18 | 2023-06-13 |
2405 | Remote code execution in cdnjs of Cloudflare |
RCE
Path traversal |
Cloudflare |
RyotaK (@ryotkak) |
Bug Bounty | 2021-07-16 | 2023-06-13 |
2321 | Why u should use burp to test Path Traversal Vulnerability and also get RXSS |
Path traversal
XSS
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2205 | RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through |
RCE
Path traversal |
Citrix Systems |
Markus Wulftange (@mwulftange) |
Bug Bounty | 2021-09-21 | 2023-06-13 |
2013 | CVE-2021-43798 - Path Traversal Vulnerability In Grafana |
Path traversal |
Grafana Labs |
Jordy Versmissen / J0VSEC (@j0v0x0) |
Bug Bounty | 2021-12-08 | 2023-06-13 |
1994 | GHSL-2021-1053: Path traversal in Grafana REST API - CVE-2021-43813, CVE-2021-43815 |
Path traversal |
Grafana Labs |
Alvaro Muñoz (@pwntester) |
Bug Bounty | 2021-12-15 | 2023-06-13 |
1967 | Common Nginx Misconfiguration leads to Path Traversal |
Path traversal |
NA |
MikeChan |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1940 | Breaking Parser Logic: Gain Access To NGINX Plus API — Read/Write Upstreams. |
Path traversal |
NA |
zoid (@z0idsec) |
Bug Bounty | 2022-01-05 | 2023-06-13 |
1918 | RCE In Adobe Acrobat Reader For Android(CVE-2021-40724) |
RCE
Path traversal
Android |
Google
Adobe |
sunny (@hulkvision) |
Bug Bounty | 2022-01-14 | 2023-06-13 |
1899 | Path Traversal Paradise |
Path traversal
LFI |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-23 | 2023-06-13 |
1827 | QRCDR ZeroDay Path Traversal Vulnerability |
Path traversal |
NA |
Farhad Karimi (@n0lsec) |
Bug Bounty | 2022-02-11 | 2023-06-13 |
1781 | Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager |
Authentication bypass
RCE
SSRF
Path traversal |
VMware |
Egor Dimitrenko (@elk0kc) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1772 | [ Directory Traversal attack ] How did I find it using GitHub |
Information disclosure
Path traversal |
NA |
Fenrir (@leetibrahim) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1764 | How I Hacked A Crypto Company And Could Steal 1 Million Dollars Worth of Bitcoin |
Path traversal |
NA |
zoid (@z0idsec) |
Bug Bounty | 2022-03-05 | 2023-06-13 |
1686 | Joomla! <= 4.1.0 (Tar.php) Zip Slip Vulnerability |
Zip Slip attack
Path traversal
Source code disclosure |
Joomla! |
Egidio Romano / EgiX |
Bug Bounty | 2022-03-29 | 2023-06-13 |
1648 | Meta%27s SparkAR RCE Via ZIP Path Traversal |
RCE
Path traversal |
Meta / Facebook |
Fady Othman (@Fady_Othman) |
Bug Bounty | 2022-04-07 | 2023-06-13 |
1632 | Bypass Apple Corp SSO on Apple Admin Panel |
Path traversal |
Apple |
Stealthy (@stealthybugs) |
Bug Bounty | 2022-04-12 | 2023-06-13 |