2065 | A Story of an Epic Blind Remote Code Execution(RCE) |
RCE
OS command injection |
NA |
Akash Solanki (@MAALP1225) |
Bug Bounty | 2021-11-18 | 2023-06-13 |
1881 | Command Injection in Google Cloud Shell |
RCE
OS command injection |
Google |
Ademar Nowasky Junior |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1819 | Advisory: Western Digital My Cloud Pro Series PR4100 RCE |
RCE
OS command injection |
Western Digital |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1809 | Advisory: Cisco RV340 Dual WAN Gigabit VPN Router (RCE over LAN) |
RCE
Unrestricted file upload
OS command injection |
Cisco |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-17 | 2023-06-13 |
1754 | SSD Advisory – NETGEAR DGND3700v2 PreAuth Root Access |
Authentication bypass
OS command injection
RCE |
Netgear |
- |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1698 | Finding bugs to trigger Unauthenticated Command Injection in a NETGEAR router (PSV-2022–0044) |
XSS
Arbitrary file read
Authentication bypass
OS command injection
RCE |
Netgear |
stypr (@stereotype32) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1677 | Pwning a Cisco RV340 with a 4 bug chain exploit |
Local Privilege Escalation
OS command injection
RCE
Session management issue |
Cisco |
Liv (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1571 | Cloudflare Pages, part 1: The fellowship of the secret |
Command injection
Container escape
Bash Path injection
RCE
Local Privilege Escalation
Information disclosure |
Cloudflare |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1496 | Multiple vulnerabilities in Zyxel zysh |
OS command injection
Memory corruption |
Zyxel |
Marco Ivaldi / Raptor (@0xdea) |
Bug Bounty | 2022-06-07 | 2023-06-13 |
1439 | Exploiting Bitdefender Antivirus: RCE from any website |
RCE
Command injection |
Bitdefender |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1372 | Hacking on a Private Program (Salseforce crm) |
RCE
OS command injection |
NA |
Maruf Hosan (@thinkermaruff) |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1314 | CVE-2022–36446 — Webmin 1.996 — Remote Code Execution (RCE — Authenticated) During Install New Packages |
RCE
OS command injection |
Webmin |
Emir Polat (@devilsgrins) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1293 | My Second CVE (CVE-2022-31855) |
OS command injection
Local Privilege Escalation |
RStudio |
y0ung_dst (@Y0ung_MA) |
Bug Bounty | 2022-07-30 | 2023-06-13 |
1279 | QNAP Poisoned XML Command Injection (Silently Patched) |
OS command injection
RCE |
QNAP |
Jake Baines (@Junior_Baines) |
Bug Bounty | 2022-08-04 | 2023-06-13 |
1263 | Advisory: Cisco Small Business RV Series Routers Web Filter Database Update Command Injection Vulnerability |
OS command injection
RCE |
Cisco |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1257 | Google Cloud Shell - Command Injection |
OS command injection
RCE
Cloud |
Google |
Bugra Eskici (@bugraeskici) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1251 | Mining Node.js Vulnerabilities via Object Dependence Graph and Query |
RCE
OS command injection
Prototype pollution
Path traversal |
NA |
Song Li |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1249 | Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software |
RCE
OS command injection
Local Privilege Escalation
MiTM |
Cisco |
Jake Baines (@Junior_Baines) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1246 | The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors |
Privilege escalation
Cross-tenant vulnerability
OS command injection
Local Privilege Escalation
Cloud |
Google
Microsoft
Aiven |
Shir Tamari (@shirtamari) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1195 | Blind command injection |
RCE
OS command injection |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-21 | 2023-06-13 |
1176 | Command Injection in the GitHub Pages Build Pipeline |
RCE
OS command injection |
GitHub |
Joren Vrancken |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1163 | Out-Of-Bond Remote code Execution(RCE) on De Nederlandsche Bank N.V. with burp-suite collaborator |
OS command injection
RCE |
De Nederlandsche Bank |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-08-28 | 2023-06-13 |
1080 | Security Advisory: NETGEAR Routers FunJSQ Vulnerabilities |
OS command injection
RCE
MiTM |
Netgear |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1079 | Breaking Bitbucket: Pre Auth Remote Command Execution (CVE-2022-36804) |
RCE
OS command injection |
Atlassian |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1046 | Exploiting Distroless Images |
Command injection
Arbitrary file read
Arbitrary file write
Container escape |
Google |
Daniel Teixeira (@TheRedOperator) |
Bug Bounty | 2022-09-22 | 2023-06-13 |