Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
979Enter "Sandbreak" - Vulnerability In vm2 Sandbox Module Enables Remote Code Execution (CVE-2022-36067) RCE Sandbox bypass vm2 Oxeye (@OxeyeSecurity) Bug Bounty2022-10-102023-06-13
972Pwning ManageEngine — From Endpoint to Exploit: A deep dive into CVE-2021–42847 Arbitrary file write XXE RCE Zoho Erik Wynter (@WynterErik) Bug Bounty2022-10-122023-06-13
950Toner Deaf – Printing your next persistence (Hexacon 2022) Path traversal Arbitrary file write RCE Printer hacking Lexmark Alex Plaskett (@alexjplaskett) Bug Bounty2022-10-172023-06-13
948Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution RCE ICONICS Sector 7 (@sector7_nl) Bug Bounty2022-10-172023-06-13
947Analysis of a Remote Code Execution (RCE) Vulnerability in Cobalt Strike 4.7.1 RCE XSS HelpSystems Rio (@0x09AL) Bug Bounty2022-10-172023-06-13
946Guest Blog Post - Memory corruption vulnerabilities in Edge Browser hacking Memory corruption Use-After-Free Out-of-bounds Read Out-of-bounds Write Microsoft David Erceg (@david_erceg) Bug Bounty2022-10-172023-06-13
945CVE 2022–24082, RCE in the PEGA Platform — Discovery, Remediation & Technical Details (Long Live JMX!!!) RCE JMX PEGA Marcin Wolak Bug Bounty2022-10-172023-06-13
943Basic recon to RCE III RCE OS command injection NA Joshua Martinelle (@J0_mart) Bug Bounty2022-10-182023-06-13
941Remote Code Execution in Melis Platform RCE Path traversal Insecure deserialization Security code review Melis Platform Karim El Ouerghemmi Bug Bounty2022-10-182023-06-13
940Yet Another Telerik UI Revisit Cryptographic issues RCE Progress (Telerik) Paul Mueller Bug Bounty2022-10-192023-06-13
936CVE-2022-3236: Sophos Firewall User Portal and Web Admin Code Injection RCE Code injection Security code review Sophos Guy Lederfein (@glederfein) Bug Bounty2022-10-192023-06-13
935Microsoft Office Online Server Remote Code Execution SSRF RCE Microsoft Manish Tanwar (@IndiShell1046) Bug Bounty2022-10-192023-06-13
931A New Attack Surface on MS Exchange Part 4 - ProxyRelay! RCE Privilege escalation Microsoft Orange Tsai (@orange_8361) Bug Bounty2022-10-192023-06-13
929Potential Remote Code Execution Vulnerability Discovered In HSQLDB RCE Security code review HSQL Development Group (HSQLDB) Code Intelligence (@CI_Fuzz) Bug Bounty2022-10-192023-06-13
922Sail away, sail away, sail away RCE Privilege escalation NA Reino Mostert Bug Bounty2022-10-212023-06-13
918Finding Multiple Security Issues on Agorapulse Log4shell RCE Information disclosure Broken Access Control Privilege escalation Agorapulse Snap Sec (@snap_sec) Bug Bounty2022-10-242023-06-13
913Remote Code Execution by Abusing Apache Spark SQL SQL injection RCE NA Colin McQueen Bug Bounty2022-10-242023-06-13
910Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager RCE Insecure deserialization Security code review VMware Sina Kheirkhah (@SinSinology) Bug Bounty2022-10-252023-06-13
895Visual Studio Code Jupyter Notebook RCE RCE XSS Arbitrary file read Electron Microsoft Luca Carettoni (@lucacarettoni) Bug Bounty2022-10-272023-06-13
894AWS SSRF to Root on production instance — A bug worth 1.75Lacs SSRF RCE Password reset NA Avinash Jain (@logicbomb_1) Bug Bounty2022-10-272023-06-13
892RCE docker api, but … RCE Docker daemon misconfiguration NA nanwn Bug Bounty2022-10-282023-06-13
890CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities RCE Phar deserialization Reflected XSS XPATH injection Path traversal LFI Juniper Paulos Yibelo (@PaulosYibelo) Bug Bounty2022-10-282023-06-13
886Old RCE worth $3362. RCE NA nanwn Bug Bounty2022-10-302023-06-13
884Vulnerabilities In Apache Batik Default Security Controls – SSRF And RCE Through Remote Class Loading SSRF RCE Apache Batik Piotr Bazydło (@chudypb) Bug Bounty2022-10-312023-06-13
874Chaining Multiple Vulnerabilities Leads to Remote Code Execution (RCE) on One of the Payment Service Companies. Exposed registration page Exposed Jenkins instance Weak credentials RCE NA Rohit Soni (@streetofhacker) Bug Bounty2022-11-022023-06-13