3983 | Privilege Escalation using Api endpoint |
Privilege escalation |
NA |
Ronak Patel (@ronak_9889) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3964 | How I upgraded my privileges to the administrator of Odnoklassniki’s url shortener |
Privilege escalation |
ok.ru |
Sergey Kashatov (@iframe0x01) |
Bug Bounty | 2019-08-20 | 2023-06-13 |
3943 | Add new user with Admin permission and takeover the organization |
Authorization flaw
Privilege escalation |
NA |
Tarek Mohamed (@Conan0x3) |
Bug Bounty | 2019-09-04 | 2023-06-13 |
3907 | Facebook Workplace Privilege Escalation Vulnerability To Change The Post Privacy As Public |
Privilege escalation |
Meta / Facebook |
Guhan Raja (@havocgwen) |
Bug Bounty | 2019-09-21 | 2023-06-13 |
3830 | Privilege Escalation with simple recon |
Privilege escalation
Blind XSS |
NA |
Mayur Gupta (@RisingHunter_) |
Bug Bounty | 2019-11-16 | 2023-06-13 |
3827 | This is How I was able to hunt a rare bug in a private program |
Missing authentication
Privilege escalation |
NA |
Abida Fahd |
Bug Bounty | 2019-11-18 | 2023-06-13 |
3746 | Bug Hunting Journey of 2019 |
XSS
Privilege escalation
Information disclosure |
Alibaba
Yahoo! / Verizon Media |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3740 | Admin capabilities around your ears |
Local Privilege Escalation |
Poly (Plantronics) |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2020-01-02 | 2023-06-13 |
3735 | How I found a Privilege Escalation Bug in a private Ecommerce? |
Privilege escalation |
NA |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-01-06 | 2023-06-13 |
3593 | EN | Administrator level Privilege Escalation story |
Privilege escalation |
NA |
Samet Sahin (@sametsahinnet) |
Bug Bounty | 2020-03-19 | 2023-06-13 |
3575 | Restriction is not a promise : Privilege escalation on Google. |
Privilege escalation
Authorization flaw |
Google |
Hariharan.s (@DJHARIZ1) |
Bug Bounty | 2020-03-30 | 2023-06-13 |
3568 | Privilege Escalation - Hello Admin |
Privilege escalation |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3541 | How was i able to find privilege escalation. |
IDOR
Authorization flaw |
NA |
Akshar Tank (@Akshar__tank) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3530 | Messenger Rooms Bug Bounty Write-up |
Privilege escalation
Authorization flaw |
Meta / Facebook |
Jane Manchun Wong (@wongmjane) |
Bug Bounty | 2020-04-24 | 2023-06-13 |
3470 | CVE-2020–1088 — Yet another arbitrary delete EoP |
Local Privilege Escalation
Windows |
Microsoft |
Søren Fritzbøger (@fritzboger) |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3442 | Analysis and Discovery of CVE-2020-13693 |
Privilege escalation
Security code review |
BBPress |
Raphael Karger (@pwnszn) |
Bug Bounty | 2020-05-29 | 2023-06-13 |
3424 | Privilege Escalation in Google Cloud Platform%27s OS Login |
Privilege escalation |
Google |
Chris Moberly (@init_string) |
Bug Bounty | 2020-06-04 | 2023-06-13 |
3422 | Three Privilege Escalation Bugs in Google Cloud Platform’s OS Login |
Local Privilege Escalation
Cloud |
Google |
initstring (@init_string) |
Bug Bounty | 2020-06-04 | 2023-06-13 |
3416 | From 3,99 to 1,650 USD (Part I) – Simple Vertical Privilege Escalation by Changing HTTP Response |
Privilege escalation |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-06-06 | 2023-06-13 |
3411 | Local Privilege Escalation Discovered in VMware Fusion |
Local Privilege Escalation
MacOS |
VMware |
Rich Mirch (@0xm1rch) |
Bug Bounty | 2020-06-09 | 2023-06-13 |
3405 | Privilege Escalation by Changing HTTP Response (Admin Access) |
Privilege escalation |
NA |
Bachrudin Ashari Pujakusuma (@Bachrudinashari) |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3277 | CVE-2020–9934: Bypassing the macOS Transparency, Consent, and Control (TCC) Framework for unauthorized access to sensitive user data |
MacOS
Local Privilege Escalation
Authorization flaw |
Apple |
Matt Shockley (@mattshockl) |
Bug Bounty | 2020-07-27 | 2023-06-13 |
3259 | CVE-2020–9854: "Unauthd" - (three) logic bugs ftw! |
Local Privilege Escalation
Logic flaw |
Apple |
Ilias Morad (@A2nkF_) |
Bug Bounty | 2020-08-01 | 2023-06-13 |
3256 | CVE-2020–9854: "Unauthd" |
MacOS
Local Privilege Escalation
SIP bypass |
Apple (macOS) |
Ilias Morad (@A2nkF_) |
Bug Bounty | 2020-08-01 | 2023-06-13 |
3250 | Amazon AWS Bastion - Logger Bypass |
Logging bypass
Local Privilege Escalation |
AWS |
Denis Andzakovic |
Bug Bounty | 2020-08-03 | 2023-06-13 |