2186 | Zero-Day: Hijacking iCloud Credentials with Apple Airtags (Stored XSS) |
Stored XSS |
Apple |
Bobby Rauch / Bobbyr |
Bug Bounty | 2021-09-28 | 2023-06-13 |
2185 | "A tale of making internet pollution free" - Exploiting Client-Side Prototype Pollution in the wild |
Prototype pollution
XSS |
Apple
Atlassian
Mozilla
HubSpot
Segment Analytics |
Sergey Bobrov (@black2fan) |
Bug Bounty | 2021-09-28 | 2023-06-13 |
2177 | Privilege Escalation to stored XSS |
Privilege escalation
HTTP response manipulation
Stored XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2021-10-01 | 2023-06-13 |
2168 | [EN] Stored XSS in the administrator’s panel due to misuse of MarkupSafe |
Stored XSS |
pass Culture |
Aethlios (@AethliosIK) |
Bug Bounty | 2021-10-06 | 2023-06-13 |
2166 | Hacking Netflix Eureka! |
SSRF
XSS |
Netflix |
Maxim Tyukov (@maxtyukov) |
Bug Bounty | 2021-10-06 | 2023-06-13 |
2159 | Stumbling across a DOM XSS on google.com |
DOM XSS |
Google |
tkiela (@svennergr) |
Bug Bounty | 2021-10-10 | 2023-06-13 |
2156 | Exploiting HTML-to-PDF Converters through HTML Imports |
XSS
LFI |
NA |
Mohammed Diaa (@mhmdiaa) |
Bug Bounty | 2021-10-10 | 2023-06-13 |
2133 | Moodle - Stored XSS and blind SSRF possible via feedback answer text |
Stored XSS
SSRF |
Moodle |
rekter0 (@rekter0) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2114 | Write Up – XSS Stored In api.media.atlassian.com Via Doc File (iOS) |
Stored XSS |
Atlassian |
Omar Espino (@omespino) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2107 | How i made 500$ with XSS |
XSS
Account takeover |
NA |
Nassim Chami (@nvccim) |
Bug Bounty | 2021-11-01 | 2023-06-13 |
2088 | Write Up – Google VRP Bug Bounty: /etc/environment Local Variables Exfiltrated On Linux Google Earth Pro Desktop App – $1,337 USD |
XSS |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2073 | Diving into Open-source LMS Codebases |
Insecure file upload
Insecure deserialization
RCE
CSRF
SQL injection
Reflected XSS |
Moodle
Chamilo LMS |
Poh Jia Hao (@Chocologicall) |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2070 | The tale of CVE-2021–34479 (VSCode XSS) |
XSS
CSP bypass |
Microsoft |
Daniel Santos (@bananabr) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2063 | Exploiting OAuth: Journey to Account Takeover |
Account takeover
OAuth
XSS
Weak CSP
CSRF |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
2059 | [BugBounty] XSS with Markdown — Exploit & Fix on OpenSource |
XSS |
NA |
Lê Thành Phúc |
Bug Bounty | 2021-11-22 | 2023-06-13 |
2055 | Finding XSS on .apple.com and building a proof of concept to leak your PII information |
XSS |
Apple |
Zseano (@zseano) |
Bug Bounty | 2021-11-23 | 2023-06-13 |
2050 | How I Found My First XSS Bug |
XSS |
Atlassian |
Thedarkwayg (@shadow_CLAY) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
2045 | SEC-596 |
Reflected XSS |
cPanel |
sh1yo (@sh1yo_) |
Bug Bounty | 2021-11-29 | 2023-06-13 |
2040 | NodeBB 1.18.4 - Remote Code Execution With One Shot |
RCE
XSS
Authentication bypass
Arbitrary file read |
NodeBB |
Sonar (@SonarSource) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2038 | VMware vCenter earlier versions (7.0.2.00100) has unauthorized arbitrary file read + ssrf + xss vulnerability |
LFI
SSRF
XSS
Arbitrary file read |
VMware |
Khoa Dinh (@_l0gg) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2037 | HTTP Header Injection In Citrix ADC And Citrix Gateway (CVE-2020-8300, CVE-2021-22927) |
Host header injection
XSS |
Citrix Systems |
Wolfgang Ettlinger |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2030 | AWS SageMaker Jupyter Notebook Instance Takeover |
Self-XSS
CSRF
RCE |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
2027 | Write Up – XSS Stored In files.slack.com Via XML/SVG File (iOS) – $1,000 USD |
XSS |
Slack |
Omar Espino (@omespino) |
Bug Bounty | 2021-12-03 | 2023-06-13 |
2012 | Account Takeover via Stored XSS |
Account takeover
Stored XSS |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
2001 | SVG based Stored XSS |
Stored XSS |
NA |
xaonan44 |
Bug Bounty | 2021-12-12 | 2023-06-13 |