4712 | Account Take over via reset password |
Password reset
Account takeover |
NA |
Yasser Gersy (@yassergersy) |
Bug Bounty | 2018-06-25 | 2023-06-13 |
4711 | Subdomain Takeover: Starbucks points to Azure |
Subdomain takeover |
Starbucks |
Patrik Hudak (@0xpatrik) |
Bug Bounty | 2018-06-25 | 2023-06-13 |
4710 | How re-signing up for an account lead to account takeover |
Logic flaw
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-06-26 | 2023-06-13 |
4709 | Take Advantage of Out-of-Scope Domains in Bug Bounty Programs |
XSS |
NA |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-06-27 | 2023-06-13 |
4708 | This popular Facebook app publicly exposed your data for years |
Information disclosure
Authorization flaw |
Meta / Facebook
Nametests.com |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2018-06-28 | 2023-06-13 |
4707 | Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud |
OS command injection
RCE |
VMware |
Brian Sullivan |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4706 | https://leigh-annegalloway.com/tumblr/ |
Captcha bypass
Username enumeration
Information disclosure |
Automattic |
Leigh-Anne Galloway (@L_AGalloway) |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4705 | Chaining Multiple Vulnerabilities to Gain Admin Access |
IDOR
Account takeover |
NA |
Ben Sadeghipour (@nahamsec) |
Bug Bounty | 2018-07-02 | 2023-06-13 |
4704 | The $12,000 Intersection between Clickjacking, XSS, and Denial of Service |
Clickjacking
XSS
DoS |
Bustabit |
Sam Curry (@samwcyo) |
Bug Bounty | 2018-07-04 | 2023-06-13 |
4703 | Latex to RCE, Private Bug Bounty Program |
RCE |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2018-07-06 | 2023-06-13 |
4702 | CVE-2016-3473 |
XXE |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2018-07-06 | 2023-06-13 |
4701 | CVE-2018-8819 |
XXE |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2018-07-07 | 2023-06-13 |
4700 | Server Side Request Forgery on Vanilla Forums |
SSRF |
Vanilla Forums |
Vikash Chaudhary (@OffensiveHunter) |
Bug Bounty | 2018-07-07 | 2023-06-13 |
4699 | #BugBounty - Compromising User Account- "How I was able to compromise user account via HTTP Parameter Pollution(HPP)" |
HTTP parameter pollution
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-07-07 | 2023-06-13 |
4698 | Persistent XSS at AH.nl |
Stored XSS |
AH.nl |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-07-09 | 2023-06-13 |
4697 | Gsuite Hangouts Chat 5k IDOR |
IDOR |
Google |
Cam (@SecretlyHidden1) |
Bug Bounty | 2018-07-10 | 2023-06-13 |
4696 | XSS in Microsoft subdomain |
XSS |
Microsoft |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2018-07-13 | 2023-06-13 |
4695 | Should this be public though? |
Information disclosure |
Shopify
Uber |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-07-13 | 2023-06-13 |
4694 | Bug Bounty at Bangladeshi Site. |
SQL injection |
NA |
Shaifullah Shaon |
Bug Bounty | 2018-07-15 | 2023-06-13 |
4693 | Attacking PostgreSQL Database |
Bruteforce
Weak credentials |
NA |
Vishnuraj |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4692 | WRITE UP – TELEGRAM BUG BOUNTY – WHATSAPP N/A [“Blind” XSS Stored iOS in messengers twins, who really care about your security?] |
Blind XSS |
Meta / Facebook |
Omar Espino (@omespino) |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4691 | CVE-2018-13784: PrestaShop 1.6.x Privilege Escalation |
Privilege escalation
Session management issue |
PrestaShop |
Charles Fol (@cfreal_) |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4690 | Hacking thousands of companies through their helpdesk |
Account takeover
DoS
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-07-17 | 2023-06-13 |
4689 | Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups |
Authorization flaw
Logic flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-07-18 | 2023-06-13 |
4688 | Hey Developer, Give me your API keys.!! |
Information disclosure |
Crowdin |
Devansh batham (@devanshwolf) |
Bug Bounty | 2018-07-18 | 2023-06-13 |