749 | Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access |
Cloud
SQL injection
Privilege escalation
Information disclosure |
IBM |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
735 | Account Takeover - Inside The Tenant |
Account takeover
Information disclosure |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-12-03 | 2023-06-13 |
728 | OTP Leaking Through Cookie Leads to Account Takeover |
Information disclosure
Account takeover |
NA |
ag3n7 |
Bug Bounty | 2022-12-05 | 2023-06-13 |
725 | How we breached ZDFheute live on television |
Information disclosure |
Zweites Deutsches Fernsehen |
CyberCitizen |
Bug Bounty | 2022-12-06 | 2023-06-13 |
722 | How you can find your first bug using google |
Information disclosure |
NA |
shbugger1 |
Bug Bounty | 2022-12-07 | 2023-06-13 |
721 | A03:2021 — [Injection] SQL Injection through internal directory disclose |
SQL injection
Information disclosure |
NA |
Tushar |
Bug Bounty | 2022-12-07 | 2023-06-13 |
716 | STRIPE Live Key Exposed:: Bounty: $1000 |
Information disclosure |
NA |
Vipul Sahu |
Bug Bounty | 2022-12-09 | 2023-06-13 |
703 | PII data exfiltration within minutes |
Information disclosure |
NA |
Mayank Garg |
Bug Bounty | 2022-12-12 | 2023-06-13 |
701 | CVE-2022-20942: It%27s not old functionality, it%27s vintage |
Information disclosure |
Cisco |
Silver Security (@SugarFiendSec) |
Bug Bounty | 2022-12-13 | 2023-06-13 |
671 | Owning half of a government assets through AWS |
Information disclosure
Hardcoded API keys |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-12-20 | 2023-06-13 |
651 | How I Pwned 10 Admin Panels and got rewarded 8000$+? |
Information disclosure
Credential stuffing |
NA |
Inderjeet Singh (@3nc0d3dGuY) |
Bug Bounty | 2022-12-25 | 2023-06-13 |
640 | Feedback Analyzer Exploitation |
Information disclosure |
NA |
hacker_might |
Bug Bounty | 2022-12-28 | 2023-06-13 |
621 | Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More |
Account takeover
SSO
RCE
Authorization bypass
SQL injection
Mass assignment
Information disclosure |
Kia
Honda
Infiniti
Nissan
Acura
Mercedes-Benz
Hyundai
Genesis
BMW
Rolls Royce
Ferrari
Spireon
Ford
Reviver
Porsche
Toyota
Jaguar
Land Rover
SiriusXM |
Sam Curry (@samwcyo) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
615 | I scanned every package on PyPi and found 57 live AWS keys |
Information disclosure |
Amazon
Intel
Stanford
The Australian Government |
Tom Forbes |
Bug Bounty | 2023-01-06 | 2023-06-13 |
589 | Critical Vulnerability through OSINT only |
Information disclosure |
NA |
Viktor Mares |
Bug Bounty | 2023-01-15 | 2023-06-13 |
576 | From Error_Log File(P4) To Company Account Takeover(P1) and Unauthorized Actions On API |
Information disclosure |
NA |
Muhanad Israiwi (@IsrewyMohand) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
574 | How I identified and reported vulnerabilities in Oracle and the rewards of responsible disclosure:From Backup Leak to Hall of Fame |
Information disclosure |
Oracle |
ParagBagul |
Bug Bounty | 2023-01-18 | 2023-06-13 |
555 | How i was able to get critical bug on google by get full access on [Google Cloud BI Hackathon] |
Information disclosure |
Google |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
537 | Disclosing Facebook page admins by playing a game |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2023-01-28 | 2023-06-13 |
536 | PHP Development Server <= 7.4.21 - Remote Source Disclosure |
Source code disclosure
Information disclosure
Security code review |
PHP |
Rahul Maini (@iamnoooob) |
Bug Bounty | 2023-01-28 | 2023-06-13 |
516 | Broken Function Level Authorization leads to disclosing PII Information of all company users |
Broken Function Level Authorization
Information disclosure |
NA |
Mirza Muhammad Fauzan |
Bug Bounty | 2023-01-31 | 2023-06-13 |
500 | Play with Google, Twitter, Apple, Dell |
XSS
HTML injection
IDOR
Information disclosure |
Google
Twitter
Apple
Dell |
rezaduty (@rezaduty) |
Bug Bounty | 2023-02-03 | 2023-06-13 |
471 | Information disclosure or GDPR breach? A Google tale… |
Privacy issue
Information disclosure
Missing authentication |
Google |
Luke Berner |
Bug Bounty | 2023-02-10 | 2023-06-13 |
434 | Found an URL in the android application source code which lead to an IDOR |
Android
Information disclosure
IDOR |
NA |
Vengeance |
Bug Bounty | 2023-02-18 | 2023-06-13 |
430 | Exposing 185M+ Indians’ Personal Information and much more |
Broken Access Control
IDOR
Information disclosure |
Aadhaar
CERT-In |
Robin Justin (@_robinjustin_) |
Bug Bounty | 2023-02-20 | 2023-06-13 |