1110 | Groovy Template Engine Exploitation – Notes from a real case scenario |
RCE
Code injection |
NA |
Gianluca Baldi (@0x_nope) |
Bug Bounty | 2022-09-07 | 2023-06-13 |
1107 | Baxter SIGMA Spectrum Infusion Pumps: Multiple Vulnerabilities (FIXED) |
Hardcoded credentials
Memory corruption
MiTM
Information disclosure |
Baxter Healthcare |
Deral Heiland (@Percent_X) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1105 | QUEST KACE Desktop Authority Pre-Auth Remote Code Execution (CVE-2021-44031) |
RCE
Path traversal |
Quest |
Tom Ellson (@tde_sec) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1100 | Riding The Inforail To Exploit Ivanti Avalanche Part 2 |
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
1091 | How I DIDN’T get an RCE in a $200 Billion company — Bug Bounty |
RCE
Components with known vulnerabilities |
NA |
nynan (@_nynan) |
Bug Bounty | 2022-09-12 | 2023-06-13 |
1090 | LiveHelperChat - Remote Code Execution via Vulnerable Theme Upload Function |
RCE |
Live Helper Chat |
Arben Shala (@arbennsh) |
Bug Bounty | 2022-09-13 | 2023-06-13 |
1088 | Hacking Unity Games with Malicious GameObjects |
Arbitrary code execution
RCE |
Unity |
Jason Kielpinski (@f2jason) |
Bug Bounty | 2022-09-13 | 2023-06-13 |
1080 | Security Advisory: NETGEAR Routers FunJSQ Vulnerabilities |
OS command injection
RCE
MiTM |
Netgear |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1079 | Breaking Bitbucket: Pre Auth Remote Command Execution (CVE-2022-36804) |
RCE
OS command injection |
Atlassian |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1071 | How i Found Unauthorized Bypass RCE |
RCE
Old components with known vulnerabilities |
NA |
Yashshirke |
Bug Bounty | 2022-09-18 | 2023-06-13 |
1058 | Securing Developer Tools: OneDev Remote Code Execution |
RCE
SSRF
Broken Access Control
Container escape |
OneDev |
Paul Gerste |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1041 | Pre-Auth Remote Code Execution - Web Page Test |
RCE
SSRF |
CatchPoint |
Laluka (@TheLaluka) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1028 | Discovering The Less-known Vulnerability In Oracle Peoplesoft |
TockenChpoken
Privilege escalation
Bruteforce
Cookie manipulation |
NA |
RE:HACK (@rehackxyz) |
Bug Bounty | 2022-09-26 | 2023-06-13 |
1024 | Two RCEs are better than one: write-up of an interesting lateral movement |
Local Privilege Escalation
RCE |
NA |
Riccardo Malatesta (@seeu_inspace) |
Bug Bounty | 2022-09-28 | 2023-06-13 |
1015 | Orange Arbitrary Command Execution |
RCE
Docker daemon misconfiguration
Missing authentication |
Orange |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
1013 | Security vs Compliance-Cloudflare Password Policy Restriction Bypass |
Client-side enforcement of server-side security |
Cloudflare |
Lohith Gowda M (@lohigowda_in) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
1012 | How Scanning Your Projects for Security Issues Can Lead to Remote Code Execution |
RCE
OS command injection |
Snyk |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
1011 | Two Lines Of JScript For $20,000 – Pwn2Own Miami 2022 |
RCE |
ICONICS |
Ben McBride (@bdmcbri) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
1009 | Tale of Easy P1 Bugs in Wild |
Forced browsing
403 bypass
Information disclosure |
NA |
Harsh Tandel |
Bug Bounty | 2022-10-01 | 2023-06-13 |
1002 | Securing Developer Tools: A New Supply Chain Attack on PHP |
Argument injection
RCE
Supply chain attack
Security code review |
Packagist |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2022-10-04 | 2023-06-13 |
1001 | Hacking TMNF: Part 1 - Fuzzing the game server |
RCE
Memory corruption
Format string vulnerability |
Ubisoft |
- |
Bug Bounty | 2022-10-05 | 2023-06-13 |
994 | CVE-2022-41343 |
RCE
Insecure deserialization
Phar deserialization |
dompdf |
Tanto Security team (@TantoSecurity) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
992 | SSD Advisory – pfSense Post Auth RCE |
RCE
Privilege escalation |
pfSense |
이예랑 (@yelang123x) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
989 | CVE-2022–36635 — A SQL Injection in ZKSecurityBio to RCE |
SQL injection |
ZKTeco |
Caio Burgardt (@CaioBurgardt) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
984 | Persistent PHP Payloads In PNGs: How To Inject PHP Code In An Image – And Keep It There ! |
Unrestricted file upload
Code injection
RCE |
NA |
Quentin Roland (@ROLANDQuentin2) |
Bug Bounty | 2022-10-10 | 2023-06-13 |