2344 | How I got Reflected Cross Site Scripting(RXSS) on Manchester Metropolitan University |
XSS |
Manchester Metropolitan University |
Santosh Bobade (@Santosh88267387) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2335 | Multiple Vulnerabilities In cPanel/WHM |
XXE
Stored XSS
Privilege escalation
CSRF
Cross-Site WebSocket Hijacking (CSWH) |
cPanel |
Adrian Tiron (@adrian__t) |
Bug Bounty | 2021-08-10 | 2023-06-13 |
2334 | OVE-20210809-0001 Visual Studio Code .ipynb Jupyter Notebook XSS (Arbitrary File Read) |
XSS
Arbitrary file read |
Microsoft |
Justin Steven (@justinsteven) |
Bug Bounty | 2021-08-11 | 2023-06-13 |
2323 | 1st Bug Bounty WriteUp: Open Redirect To XSS on Login Page |
Open redirect
XSS |
NA |
Nassim Chami (@nvccim) |
Bug Bounty | 2021-08-15 | 2023-06-13 |
2321 | Why u should use burp to test Path Traversal Vulnerability and also get RXSS |
Path traversal
XSS
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2315 | How to Hack Apple ID |
XSS
Account takeover |
Apple |
Zemnmez (@zemnmez) |
Bug Bounty | 2021-08-17 | 2023-06-13 |
2307 | MonkeyType.com Stored Cross-Site Scripting |
Stored XSS
Authentication bypass
IDOR |
MonkeyType.com |
Tyle Butler (@tbutler0x90) |
Bug Bounty | 2021-08-22 | 2023-06-13 |
2306 | Story Of Unexpected Bugs |
IDOR
XSS |
NA |
Neh Patel (@thecyberneh) |
Bug Bounty | 2021-08-22 | 2023-06-13 |
2291 | Reflective XSS via search box [Bypassing Cloudflare WAF]. |
Reflected XSS |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2284 | Cache Poisoning via SelfXSS + Path Parameter |
XSS
Web cache poisoning |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2021-08-28 | 2023-06-13 |
2279 | Hunting for XSS with CodeQL |
XSS |
GitLab |
Daniel Santos (@bananabr) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2265 | How I Found Multiple XSS in Hidden Legacy Pages |
XSS |
NA |
Marx Chryz |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2264 | chaining bugs from self XSS to account takeover |
Self-XSS
WAF bypass
CSRF
Account takeover |
NA |
Behnam Yazdanpanah (@abhiunix) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2262 | SQL injection in harvard subdomain |
XSS
SQL injection |
Harvard University |
Brandon Roldan (@tomorrowisnew_) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2244 | SSRF in PDF export with PhantomJs |
SSRF
XSS
LFI |
NA |
أنس روبي (@xhzeem) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2243 | 5 Different Vulnerabilities in Google’s Threadit |
DOM XSS
Clickjacking
Privilege escalation
Information disclosure |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2241 | Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser |
Stored XSS
Local File Read |
Opera |
Renwa (@RenwaX23) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2239 | Account Takeover via XSS in e-signature feature worth 2500$ |
XSS
Account takeover |
NA |
Gökhan Güzelkokar (@gkhck_) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2234 | Mistuned Part 1: Client-side XSS to Calculator and More |
XSS
Memory corruption
iOS |
Apple |
CodeColorist (@codecolorist) |
Bug Bounty | 2021-09-10 | 2023-06-13 |
2223 | Microsoft Azure Portal – Persistent Cross-Site Scripting |
Stored XSS |
Microsoft |
Christian Becker (@0xchrisb) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2218 | How I was able to find 100+ XSS in United nations Bug Bounty Program |
XSS |
United Nations |
mrpentestguy (@MR_iambatman) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2217 | Weaponizing Reflected XSS to Account Takeover |
XSS
Account takeover |
NA |
Hassan Shahid (@pwnsauc3) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2209 | Chaining bugs for better bounties |
SSRF
XSS
Information disclosure |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-09-19 | 2023-06-13 |
2202 | mXSS in support.mozilla.org |
XSS |
Mozilla |
Guilherme Keerok (@k33r0k) |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2195 | $8,000 Bug Bounty Highlight: XSS to RCE in the Opera Browser |
XSS
RCE |
Opera |
Renwa (@RenwaX23) |
Bug Bounty | 2021-09-24 | 2023-06-13 |