2145 | Exploitation of file’s download parameters to create potential risk of malware delivery: $200 bug! |
CSRF
RCE |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-10-17 | 2023-06-13 |
2139 | A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection |
SQL injection
WAF bypass |
AWS |
Marc Olivier Bergeron |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2071 | Keybase App Vulnerability: Incomplete Cleanup of Messages In Keybase for Android/iOS, CVE-2021-34421 |
Information disclosure |
Keybase |
Olivia O’Hara (@oliviaohara) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
1855 | HigherLogic Community RCE Vulnerability |
Insecure deserialization
RCE |
8x8
IBM |
0daystolive (@0daystolive) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1837 | SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999) |
Local Privilege Escalation |
Microsoft |
Olivier Lyak (@ly4k_) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1817 | Trim private live videos and access them (Meta bug bounty) |
IDOR |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1753 | Demographic Misconfiguration on Facebook live |
Logic flaw
Authorization flaw |
Meta / Facebook |
Prajwol Dhungana (@PrajwolDhunga14) |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1677 | Pwning a Cisco RV340 with a 4 bug chain exploit |
Local Privilege Escalation
OS command injection
RCE
Session management issue |
Cisco |
Liv (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1676 | Small bugs are more dangerous than you think |
Self-XSS
Stored XSS
Open redirect
CSRF |
NA |
Liv Matan (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1561 | Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923) |
Active Directory Privilege Escalation |
Microsoft |
Oliver Lyak (@ly4k_) |
Bug Bounty | 2022-05-10 | 2023-06-13 |
1507 | Abusing Facebook’s feature for a permanent account confusion(logic vulnerability) |
MFA bypass
DoS
Logic flaw |
Meta / Facebook |
Liv |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1444 | XSS Vulnerability in IBM Content Navigator (CVE-2020-4757) |
XSS |
IBM |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-06-21 | 2023-06-13 |
1138 | Viewing Instagram live streams anonymously without notifying the host |
IDOR
Logic flaw
Privacy issue |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1090 | LiveHelperChat - Remote Code Execution via Vulnerable Theme Upload Function |
RCE |
Live Helper Chat |
Arben Shala (@arbennsh) |
Bug Bounty | 2022-09-13 | 2023-06-13 |
967 | Compromising a Backup System by iSCSI Interface During a Routine Penetration Test |
Missing authentication |
NA |
Bruno Oliveira |
Bug Bounty | 2022-10-13 | 2023-06-13 |
945 | CVE 2022–24082, RCE in the PEGA Platform — Discovery, Remediation & Technical Details (Long Live JMX!!!) |
RCE
JMX |
PEGA |
Marcin Wolak |
Bug Bounty | 2022-10-17 | 2023-06-13 |
939 | Vulnerabilities in Tenda%27s W15Ev2 AC1200 Router |
OS command injection
Buffer Overflow
Memory corruption
Stored XSS
Authorization flaw
Information disclosure |
Tenda |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
906 | GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown |
OS command injection
Arbitrary file read
Information disclosure
Account takeover
Stored XSS
Lack of rate limiting
Weak credentials
Password policy bypass |
GL.iNet |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
725 | How we breached ZDFheute live on television |
Information disclosure |
Zweites Deutsches Fernsehen |
CyberCitizen |
Bug Bounty | 2022-12-06 | 2023-06-13 |
723 | Cool Vulns Don%27t Live Long - Netgear And Pwn2Own |
Code injection
RCE
Security code review |
Netgear |
Kevin Denis |
Bug Bounty | 2022-12-06 | 2023-06-13 |
716 | STRIPE Live Key Exposed:: Bounty: $1000 |
Information disclosure |
NA |
Vipul Sahu |
Bug Bounty | 2022-12-09 | 2023-06-13 |
615 | I scanned every package on PyPi and found 57 live AWS keys |
Information disclosure |
Amazon
Intel
Stanford
The Australian Government |
Tom Forbes |
Bug Bounty | 2023-01-06 | 2023-06-13 |
569 | EmojiDeploy: Smile! Your Azure web service just got RCE’d ._. |
RCE
Cloud
CSRF
CORS misconfiguration |
Microsoft (Azure) |
Liv Matan (@terminatorLM) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
427 | Escaping misconfigured VSCode extensions |
Path traversal
DNS rebinding
XSS
HTML injection
Webview
CSP bypass |
Microsoft (SARIF viewer & Live Preview) |
Vasco Franco |
Bug Bounty | 2023-02-21 | 2023-06-13 |
154 | Never Connect to RDP Servers Over Untrusted Networks |
RDP |
Microsoft |
Olivier Bilodeau (@obilodeau) |
Bug Bounty | 2023-04-26 | 2023-06-13 |