81 | DLL Hijacking Strikes Back: Exploiting Windows on ARM RDP Client (CVE-2023-24905) |
DLL Hijacking
Local Privilege Escalation |
Microsoft (Windows) |
Dor Dali |
Bug Bounty | 2023-05-17 | 2023-06-13 |
80 | Arbitrary email forgery in Webflow |
Email spoofing
Phishing |
Webflow |
Antoine Carrincazeaux |
Bug Bounty | 2023-05-17 | 2023-06-13 |
79 | KeePass Master Password Exploit - CVE-2023-32784 - Proof Of Concept (POC) |
Plaintext Storage of a Password
Thick client |
KeePass |
Luke Kavanagh |
Bug Bounty | 2023-05-17 | 2023-06-13 |
78 | A $1,000,000 bounty? The KuCoin User Information Leak |
Information disclosure
Zendesk
Authorization flaw
Security misconfiguration |
NA |
Corben Leo (@hacker_) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
77 | How Misconfigured and Vulnerable Devices Could Expose Your Company to Physical and Cyber Threats |
IoT
Default credentials
Internal pentest |
NA |
Arben Shala (@arbennsh) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
76 | Stored Iframe Injection & Permanent Open Redirection - Zero Day |
HTML injection
Open redirect |
Discourse |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
75 | Blind OS Command Injection via Activation Request |
OS command injection |
NA |
Arumusutakimu (@arumusutakimu) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
74 | Blind OS Command Injection via Activation Request |
Memory corruption
Buffer Overflow
Out-of-bounds Read |
VMware |
Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
73 | Official extension spoofing attacks: when trusted add-ons are not so trusted |
Extension spoofing
Account takeover
XSS |
NA |
Yesenia Trejo (@Yess_2021xD) |
Bug Bounty | 2023-05-19 | 2023-06-13 |
72 | DNS Recursion Leads to DoS Attack Vivo Play (IPTV) — CVE-2023–31893 |
DoS |
Vivo |
Shooter |
Bug Bounty | 2023-05-20 | 2023-06-13 |
71 | Exposing iCloud user’s Name, phone numbers, and email addresses. |
Information disclosure |
Apple (iCloud) |
Renganathan (@IamRenganathan) |
Bug Bounty | 2023-05-20 | 2023-06-13 |
70 | Why You Should Always Check The Audit Log [Medium] — $500 |
Information disclosure |
NA |
Emanuel Beni Harijanto |
Bug Bounty | 2023-05-20 | 2023-06-13 |
69 | Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large Online Media Leader |
SQL injection |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-05-20 | 2023-06-13 |
68 | AEM Bug in Adobe |
AEM
Missing authentication
Security misconfiguration |
Adobe |
Muhammad Mater (@micro0x00) |
Bug Bounty | 2023-05-20 | 2023-06-13 |
67 | 2FA Bypass Using Custom Cookie Parameter |
MFA bypass
Android |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
66 | I helped a top Indian health benefits management platform from major PII leak by hacking their SQL Servers, AWS instance, DCs etc. |
SQL injection |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
65 | Azure DNS Takeover @ Swisscom |
DNS takeover |
Swisscom |
Hussein Ayoub |
Bug Bounty | 2023-05-22 | 2023-06-13 |
64 | Red team: Journey from RCE to have total control of cloud infrastructure |
RCE
SSTI
Container escape
Kubernetes
Components with known vulnerabilities
CI/CD |
NA |
Quang Vo (@mr_r3bot) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
63 | CVE 2023 25690 - Proof of Concept |
HTTP Request Smuggling
HTTP request splitting
CRLF injection |
Apache HTTP Server |
dhmosfunk (@DSkfunk) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
62 | Tampering with Conditional Access Policies Using Azure AD Graph API |
Cloud
Privilege escalation |
Microsoft (Azure) |
Secureworks Counter Threat Unit (@Secureworks) |
Bug Bounty | 2023-05-23 | 2023-06-13 |
61 | From Response To Request, Adding Your Own Variables Inside Of GraphQL Queries For Account Take Over |
GraphQL
IDOR
Mass assignment |
NA |
Tom Neaves |
Bug Bounty | 2023-05-23 | 2023-06-13 |
60 | Salt Labs exposes a new vulnerability in popular OAuth framework, used in hundreds of online services |
OAuth
Account takeover |
Expo
Codeacademy.com |
Aviad Carmel (@AviadCarmel) |
Bug Bounty | 2023-05-24 | 2023-06-13 |
59 | GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure |
Cloud
Privilege escalation |
Google (GCP) |
Ofir Balassiano (@ofir_balassiano) |
Bug Bounty | 2023-05-24 | 2023-06-13 |
58 | Unintended Path to Exam Domination - AWS EC2 Meta-Data |
Cloud
Privilege escalation |
NA |
Dr. Michael Gschwender (@rootcathacking) |
Bug Bounty | 2023-05-24 | 2023-06-13 |
57 | how I found a tricky XSS |
XSS |
NA |
Ziad Ali |
Bug Bounty | 2023-05-24 | 2023-06-13 |