1229 | Remote Code Execution on Element Desktop Application using Node Integration in Sub Frames Bypass - CVE-2022-23597 |
RCE
XSS |
Matrix (Element) |
s1r1us (@s1r1u5_) |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1220 | Salesforce bug hunting to Critical bug |
Information disclosure
Salesforce |
NA |
Vuk Ivanovic |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1219 | We discovered major vulnerabilities in Control Web Panel. Here’s how we found them. |
Path traversal
RCE
Weak crypto
Password reset
Account takeover |
Centos Web Panel (CWP) |
Immersive Labs (@immersivelabs) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1218 | CVE-2022-30211: Windows L2TP VPN Memory Leak and Use after Free Vulnerability |
Memory corruption
RCE |
Microsoft |
Alex Nichols (@i4mchr00t) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1210 | RCE on Spip and Root-Me, v2! |
RCE
SSTI
DNS rebinding
XSS
Code injection
Unrestricted file upload |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1196 | Failed Coding Assessment to Remote Code Execution - Part 1 |
RCE |
HackerEarth |
Akash Chhabra (@_hackingguy) |
Bug Bounty | 2022-08-20 | 2023-06-13 |
1195 | Blind command injection |
RCE
OS command injection |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-21 | 2023-06-13 |
1188 | Paracosme - CVE-2022-33318 - Remote Code Execution in ICONICS Genesis64 |
Memory corruption
RCE |
ICONICS |
Axel Souchet (@0vercl0k) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1186 | But You Told Me You Were Safe: Attacking The Mozilla Firefox Renderer (Part 1) |
Browser hacking
RCE
Prototype pollution |
Mozilla |
Hossein Lotfi (@hosselot) |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1184 | Securing Developer Tools: Argument Injection in Visual Studio Code |
Argument injection
RCE |
Microsoft |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1179 | Crashing Industrial Control Systems at Pwn2Own Miami 2022 |
DoS
Memory corruption
RCE |
Unified Automation |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1178 | SATisfying our way into remote code execution in the OPC UA industrial stack |
Memory corruption
RCE |
Unified Automation |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1176 | Command Injection in the GitHub Pages Build Pipeline |
RCE
OS command injection |
GitHub |
Joren Vrancken |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1173 | Break the Logic: 5 Different Perspectives in Single Page (€1500) |
Client-side enforcement of server-side security
IDOR
Authorization flaw |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-08-26 | 2023-06-13 |
1171 | Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later |
RCE |
Nintendo |
xcellerator (@TheXcellerator) |
Bug Bounty | 2022-08-27 | 2023-06-13 |
1163 | Out-Of-Bond Remote code Execution(RCE) on De Nederlandsche Bank N.V. with burp-suite collaborator |
OS command injection
RCE |
De Nederlandsche Bank |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-08-28 | 2023-06-13 |
1160 | Blind Exploits To Rule Watchguard Firewalls |
XPath injection
Memory corruption
Local Privilege Escalation
RCE |
WatchGuard |
Charles Fol (@cfreal_) |
Bug Bounty | 2022-08-29 | 2023-06-13 |
1159 | Bypassing ModSecurity for RCEs |
WAF bypass
Code injection
RCE |
ModSecurity |
Somdev Sangwan (s0md3v) |
Bug Bounty | 2022-08-29 | 2023-06-13 |
1145 | How did we Found Log4shell on Agorapulse |
Log4shell
RCE |
Agorapulse |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-09-01 | 2023-06-13 |
1135 | How I found my first SSRF to RCE! |
IDOR
SSRF
RCE |
NA |
Md. Asif Hossain (@0x0asif) |
Bug Bounty | 2022-09-04 | 2023-06-13 |
1131 | Hacking My Helium Crypto Miner |
Hardcoded credentials
Missing authentication
RCE
Local Privilege Escalation |
Pycom |
Md. Asif Hossain (@0x0asif) |
Bug Bounty | 2022-09-05 | 2023-06-13 |
1127 | CVE-2022-34715: More Microsoft Windows NFS V4 Remote Code Execution |
RCE
Memory corruption |
Microsoft |
Quintin Crist |
Bug Bounty | 2022-09-06 | 2023-06-13 |
1125 | CVE-2022-35405 Manage engines RCE (Password Manager Pro, PAM360 and Access Manager Plus) |
RCE |
Zoho |
Vinicius Pereira (@big0x75) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1114 | Groovy Template Engine Exploitation – Notes from a real case scenario |
RCE |
NA |
Gianluca Baldi (@0x_nope) |
Bug Bounty | 2022-09-07 | 2023-06-13 |
1112 | Exploiting Laravel based applications with leaked APP_KEYs and Queues |
RCE |
NA |
Timo Müller (@mtimo44) |
Bug Bounty | 2022-09-07 | 2023-06-13 |