56 | Hacking my “smart” toothbrush |
IoT
Reverse engineering
NFC |
NA |
Cyrill Künzi |
Bug Bounty | 2023-05-24 | 2023-06-13 |
55 | XSS Via Qr Code |
XSS |
NA |
Ahmed Osama (A0G) |
Bug Bounty | 2023-05-25 | 2023-06-13 |
54 | Ericsson Sensitive Data Exposure via Trace.axd |
Information disclosure |
Ericsson |
David Sopas (@dsopas) |
Bug Bounty | 2023-05-25 | 2023-06-13 |
53 | Exploiting The Sonos One Speaker Three Different Ways: A Pwn2Own Toronto Highlight |
Memory corruption
RCE
Out-of-bounds Read |
Sonos |
The ZDI Research Team (@thezdi) |
Bug Bounty | 2023-05-25 | 2023-06-13 |
52 | Exploring Three Remote Code Execution Vulnerabilities in RPC Runtime |
RCE
MS-RPC
Integer overflow
Memory corruption |
Microsoft (Windows) |
Ben Barnea (@nachoskrnl) |
Bug Bounty | 2023-05-26 | 2023-06-13 |
51 | Utilizing Historical URLs of an Organization to successfully execute SQL queries — Blind SQLi |
Blind SQL injection |
NA |
Aayush Vishnoi (@AayushVishnoi10) |
Bug Bounty | 2023-05-26 | 2023-06-13 |
50 | Find out the IP address through a call to Telegram… |
Privacy issue
Information disclosure |
Telegram |
Igor S. Bederov |
Bug Bounty | 2023-05-28 | 2023-06-13 |
49 | Anonymised Penetration Test Report |
Internal pentest
RCE
ADCS
Active Directory
Kerberos
DHCPv6
LLMNR |
NA |
Volkis (@VolkisAU) |
Bug Bounty | 2023-05-28 | 2023-06-13 |
48 | The 30000$ Bounty Affair. |
RCE
Missing authentication
Exposed Jenkins instance |
NA |
Gokulsspace (@GokTest) |
Bug Bounty | 2023-05-28 | 2023-06-13 |
47 | XSS in WordPress via open embed auto discovery |
XSS
postMessage |
WordPress |
Jakub Żoczek (@zoczus) |
Bug Bounty | 2023-05-29 | 2023-06-13 |
46 | Exploit an unexploitable XSS via an open redirect — A Real-Life Scenario from a Hacker’s Mindset |
XSS
Open redirect |
NA |
Ziad Ali |
Bug Bounty | 2023-05-29 | 2023-06-13 |
45 | Hunting For Password Reset Tokens By Spraying And Using HTTP Pipelining |
Password reset
Account takeover |
NA |
Tom Neaves |
Bug Bounty | 2023-05-30 | 2023-06-13 |
44 | VSCode Remote Code Execution advisory |
RCE
Thick client
Local Privilege Escalation |
Microsoft VSCode) |
Ammar Askar |
Bug Bounty | 2023-05-30 | 2023-06-13 |
43 | New macOS vulnerability, Migraine, could bypass System Integrity Protection |
SIP bypass |
Apple (macOS) |
Jonathan Bar Or (@yo_yo_yo_jbo) |
Bug Bounty | 2023-05-30 | 2023-06-13 |
42 | Vulnerabilities In Apache Commons-Text 1.10.0 |
Path traversal
XXE |
Apache Commons Text |
Chris (@mc_0wn) |
Bug Bounty | 2023-05-30 | 2023-06-13 |
41 | an offensive look at docker desktop extensions |
OS command injection
Container security |
Docker |
Leon Jacobs (@leonjza) |
Bug Bounty | 2023-05-30 | 2023-06-13 |
40 | Kramer VIA GO² – Multiple issues |
RCE
SQL injection
Arbitrary file upload
Arbitrary file read |
Kramer |
Jim Rush (@JimSRush) |
Bug Bounty | 2023-05-31 | 2023-06-13 |
39 | Reverse Engineering Coin Hunt World’s Binary Protocol |
Reverse engineering
Spoofing |
Coin Hunt World |
qkchambers |
Bug Bounty | 2023-05-31 | 2023-06-13 |
38 | Ghost Sites: Stealing Data From Deactivated Salesforce Communities |
Salesforce
Security misconfiguration |
NA |
Nitay Bachrach |
Bug Bounty | 2023-05-31 | 2023-06-13 |
37 | Anatomy of an IoT Exploit, from Hands-On to RCE |
IoT
RCE
Buffer Overflow
Memory corruption |
Wavlink |
David Baker |
Bug Bounty | 2023-06-01 | 2023-06-13 |
36 | CVE-2023-24941: Microsoft Network File System Remote Code Execution |
RCE
NFS |
Microsoft (Windows) |
Quinton Crist |
Bug Bounty | 2023-06-01 | 2023-06-13 |
35 | Bypassing An Industry-Leading WAF and Exploiting SQLi |
SQL injection
WAF bypass |
NA |
Adeeb Shah |
Bug Bounty | 2023-06-01 | 2023-06-13 |
34 | RCE via LDAP truncation on hg.mozilla.org |
RCE
LDAP truncation
Security code review |
Mozilla |
joernchen (@joernchen) |
Bug Bounty | 2023-06-03 | 2023-06-13 |
33 | Prototype Pollution Akamai |
Client-side prototype pollution
WAF bypass |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2023-06-03 | 2023-06-13 |
32 | Rate Limit Bypass Leads to 0 Click ATO |
Rate limiting bypass
Bruteforce
Password reset
Account takeover |
NA |
ZeroXUF (@ZeroXUF) |
Bug Bounty | 2023-06-04 | 2023-06-13 |