4687 | Oracle WebLogic - Multiple SAML Vulnerabilities (CVE-2018-2998/CVE-2018-2933) |
SAML
Authentication bypass |
Oracle (WebLogic) |
Denis Andzakovic |
Bug Bounty | 2018-07-18 | 2023-06-13 |
4686 | How I was able to delete 13k+ Microsoft Translator projects |
CSRF
IDOR |
Microsoft |
Haider Mahmood (@haiderinfosec) |
Bug Bounty | 2018-07-19 | 2023-06-13 |
4685 | RCE on Yahoo Luminate |
RCE |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-07-19 | 2023-06-13 |
4684 | The call is coming from inside the house — DNS rebinding in EOSIO keosd wallet |
DNS rebinding |
EOSIO |
François Proulx (@francoisproulx) |
Bug Bounty | 2018-07-19 | 2023-06-13 |
4683 | Into the Borg – SSRF inside Google production network |
SSRF |
Google |
Enguerran Gillier (@opnsec) |
Bug Bounty | 2018-07-20 | 2023-06-13 |
4682 | RCE due to ShowExceptions |
RCE
Information disclosure
Debugging enabled |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2018-07-20 | 2023-06-13 |
4681 | Google Assistant Bug Worth $3133.7 ! |
Reflected XSS |
Google |
Circle Ninja (@circleninja) |
Bug Bounty | 2018-07-21 | 2023-06-13 |
4680 | Unclaimed Medium Publication takeover in WeTransfer |
Medium publication takeover
Broken link hijacking |
WeTransfer |
Prial Islam Khan (@prial261) |
Bug Bounty | 2018-07-21 | 2023-06-13 |
4679 | IDOR FACEBOOK: malicious person add people to the "Top Fans" |
IDOR |
Meta / Facebook |
Jafar Abo Nada (@Jafar_Abo_Nada) |
Bug Bounty | 2018-07-21 | 2023-06-13 |
4678 | Finding hidden gems vol. 1: forging OAuth tokens using discovered client id and client secret |
Information disclosure |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2018-07-23 | 2023-06-13 |
4677 | Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again |
Open redirect
RCE |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2018-07-24 | 2023-06-13 |
4676 | Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=3.1.3 [CVE-2018-14716] |
SSTI |
SEOmatic CMS plugin |
Sebastian (ha.cker.info) |
Bug Bounty | 2018-07-24 | 2023-06-13 |
4675 | SQL Injection and A silly WAF |
SQL injection |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2018-07-25 | 2023-06-13 |
4674 | Exfiltration via CSS Injection |
CSS injection |
NA |
d0nut (@d0nutptr) |
Bug Bounty | 2018-07-25 | 2023-06-13 |
4673 | How I found XSS on Amazon? |
XSS |
Amazon (CloudFront) |
Coding_Karma (@karma_coded) |
Bug Bounty | 2018-07-26 | 2023-06-13 |
4672 | Binary.com ClickJacking Vulnerability — Exploiting HTML5 Security Features |
Clickjacking |
Binary.com |
Ameer Assadi (@AmeerAssadi) |
Bug Bounty | 2018-07-28 | 2023-06-13 |
4671 | Making a Blind SQL Injection a Little Less Blind |
SQL injection |
NA |
TomNomNom (@tomnomnom) |
Bug Bounty | 2018-07-28 | 2023-06-13 |
4670 | Microsoft Office 365 Stored XSS |
Stored XSS |
Microsoft |
Pethuraj (@Pethuraj) |
Bug Bounty | 2018-07-29 | 2023-06-13 |
4669 | Yahoo — Two XSSi vulnerabilities chained to steal user information. ($750 Bounty) |
XSSI |
Yahoo! / Verizon Media |
Brian Hyde (@0xHyde) |
Bug Bounty | 2018-07-29 | 2023-06-13 |
4668 | Hacking Imgur for Fun and Profit |
Outdated component with a known vulnerability
Information disclosure |
Imgur |
Nathan (@NathOnSecurity) |
Bug Bounty | 2018-07-29 | 2023-06-13 |
4667 | How I could access your internal servers, steal and modify your image repository |
RCE |
NA |
thehackerish (@thehackerish) |
Bug Bounty | 2018-07-31 | 2023-06-13 |
4666 | CRLF Injection Into PHP’s cURL Options |
CRLF injection |
NA |
TomNomNom (@tomnomnom) |
Bug Bounty | 2018-08-01 | 2023-06-13 |
4665 | Shipt Subdomain TakeOver via HeroKu ( test.shipt.com ) |
Subdomain takeover |
Shipt |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-08-01 | 2023-06-13 |
4664 | Exploiting a Microsoft Edge Vulnerability to Steal Files |
SOP bypass |
Microsoft |
Ziyahan Albeniz (@ziyaxanalbeniz) |
Bug Bounty | 2018-08-01 | 2023-06-13 |
4663 | Discovering and Exploiting a Vulnerability in Android’s Personal Dictionary (CVE-2018-9375) |
Privilege escalation
Android |
Google |
Daniel Kachakil (@Kachakil) |
Bug Bounty | 2018-08-01 | 2023-06-13 |