2723 | [Google VRP] How I Get Blind XSS At Google With Dork (First Bounty and HOF ) |
Blind XSS |
Google |
Rio Mulyadi (@riomulyadi_) |
Bug Bounty | 2021-03-11 | 2023-06-13 |
2721 | Finding keys under the door |
Stored XSS
Unrestricted file upload |
Paytm |
Naveen Prakaasham K S V |
Bug Bounty | 2021-03-12 | 2023-06-13 |
2708 | Chaining bugs for the greater good |
Blind XSS
CSRF |
NA |
mohamad mahmoudi (@Lotus_619) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2706 | TikTok for Android 1-Click RCE |
RCE
XSS
Insecure intent
Android |
TikTok |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2703 | A short story about an XSS in chat.mozilla.org (CVE-2021-21320) |
XSS |
Mozilla |
Guilherme Keerok (@k33r0k) |
Bug Bounty | 2021-03-19 | 2023-06-13 |
2698 | Finding My First Critical Vulnerability |
Information disclosure |
NA |
Thexssrat (@theXSSrat) |
Bug Bounty | 2021-03-21 | 2023-06-13 |
2693 | How I leveraged XSS to make Privilege Escalation to be Super Admin! |
XSS
Privilege escalation |
NA |
Asem Eleraky (@melotover) |
Bug Bounty | 2021-03-25 | 2023-06-13 |
2692 | PoC: The easiest 125 Euro’s I Ever made |
Logic flaw |
NA |
Thexssrat (@theXSSrat) |
Bug Bounty | 2021-03-25 | 2023-06-13 |
2691 | Encrypted Payload -> Decrypted Execution ($600) : Stored XSS |
Stored XSS |
NA |
Shrirang Diwakar |
Bug Bounty | 2021-03-25 | 2023-06-13 |
2683 | A weird XSS |
Reflected XSS |
NA |
gato the wizard |
Bug Bounty | 2021-03-30 | 2023-06-13 |
2682 | I felt like there were no more bugs left after winning € 2000 … But an email worth €750 changed my mind |
Broken Access Control
IDOR |
NA |
Thexssrat (@theXSSrat) |
Bug Bounty | 2021-03-31 | 2023-06-13 |
2672 | XSS in Large Messenger and Payment App - a Shout Out to Parameter Guessing |
XSS
HTML injection |
NA |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2671 | Bragging Rights: Let’s head back to bug bucket |
XSS
IDOR
MFA bypass |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2669 | Automate Cache Poisoning Vulnerability - Nuclei |
Web cache poisoning
Stored XSS |
NA |
Mohamed Elbadry (@_melbadry9) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2665 | Journeys in Quoteless and Multi Reflection XSS |
XSS |
NA |
Bend Theory (@bendtheory) |
Bug Bounty | 2021-04-04 | 2023-06-13 |
2663 | Breaking GitHub Private Pages for $35k |
XSS
CRLF injection
Web cache poisoning |
GitHub |
Robert Chen (@NotDeGhost) |
Bug Bounty | 2021-04-04 | 2023-06-13 |
2654 | (CRITICAL) Blind Storage XSS — My first Bug Bounty 💰 |
Blind XSS |
CS Money |
Benjamin Walter |
Bug Bounty | 2021-04-08 | 2023-06-13 |
2641 | How I got 9000 USD by hacking into iCloud |
XSS |
Apple |
Alexandre Fernandes (@fernale) |
Bug Bounty | 2021-04-15 | 2023-06-13 |
2638 | How I earned $$$$ through Stored XSS |
Stored XSS
CSTI |
NA |
Harish |
Bug Bounty | 2021-04-16 | 2023-06-13 |
2633 | XSS via Exif Data - The P2 Elevator |
Stored XSS |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2631 | Pwning your assignments: Stored XSS via GraphQL endpoint |
Stored XSS
GraphQL |
NA |
Kartik Sharma (@dominat0r98) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2621 | DMCA.COM Hack, Full Disclosure (With Proof-of-Concept) |
Privilege escalation
Client-side enforcement of server-side security
Stored XSS
Broken Access Control |
DMCA |
Joël Aviad Ossi |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2620 | How I was able to inject XSS payload into any user%27s mailbox |
XSS |
NA |
Gaurav Popalghat (@N008x) |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2615 | Telegram bug bounties: XSS, privacy issues, official bot exploitation and more… |
XSS
Authorization flaw
DoS |
NA |
Davide |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2606 | Reflected XSS on Microsoft |
Reflected XSS |
Microsoft |
N45HT |
Bug Bounty | 2021-04-25 | 2023-06-13 |