1998 | How I found XSS vulnerability in Amazon in 5 minutes using shodan |
XSS |
Amazon |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2021-12-15 | 2023-06-13 |
1989 | Yes, fun browser extensions can have vulnerabilities too! |
XSS
Browser extension hacking
postMessage |
Meow |
Wladimir Palant (@WPalant) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1988 | Stored XSS by bypassing signature |
XSS
Unrestricted file upload |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1969 | XSS via file upload |
XSS
Unrestricted file upload |
NA |
Jay Sharma |
Bug Bounty | 2021-12-27 | 2023-06-13 |
1961 | Google Cloud Shell XSS |
XSS |
Google |
NDevTK (@ndevtk) |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1924 | Pwning the portal: from database dump to session hijacking |
SQL injection
XSS
CSRF |
NA |
Bitcrack (@bitcrack_cyber) |
Bug Bounty | 2022-01-12 | 2023-06-13 |
1921 | Xiaomi Execute Arbitrary JavaScript |
XSS
HTML injection
Android |
Xiaomi |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-01-13 | 2023-06-13 |
1920 | XSS Filter Evasion + IDOR |
XSS
IDOR |
NA |
JM Sanchez / 0xEchidonut (@jmrcsnchz) |
Bug Bounty | 2022-01-13 | 2023-06-13 |
1917 | 120 Days of High Frequency Hunting |
SSRF
LFI
Information disclosure
Broken Access Control
Authentication bypass
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-15 | 2023-06-13 |
1913 | Critical XSS in chrome extension |
XSS
postMessage |
NA |
p3rr0 (@Hperalta89) |
Bug Bounty | 2022-01-17 | 2023-06-13 |
1901 | 120 Days of Frequent Hacking |
SSRF
LFI
Information disclosure
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-21 | 2023-06-13 |
1895 | First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft |
XSS |
Microsoft |
Aidil Arief |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1892 | Hacking the Apple Webcam (again) |
Universal XSS
Browser hacking |
Apple |
Ryan Pickren |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1878 | How I Made $16,500 Hacking CDN Caching Servers — Part 1 |
Web cache poisoning
Stored XSS
Web cache deception |
NA |
Kevin (@bxmbn) |
Bug Bounty | 2022-01-29 | 2023-06-13 |
1875 | XSS via X-Forwarded-Host header |
XSS
Host header injection |
Omise |
Abhijeet Biswas (@abhijeetbiswas_) |
Bug Bounty | 2022-01-30 | 2023-06-13 |
1873 | Stored Cross-Site Scripting in MediaWiki |
Stored XSS |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1866 | A Peculiar Case of XSS and my first bug |
XSS |
Bentley Systems |
Aman Pareek (@aman_notsogreat) |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1862 | My experience of Hacking The Dutch Government |
XSS |
Dutch Government |
Phenomenal (@Chawla12111) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1860 | My first bounty, IDOR + Self XSS [€3000] |
Self-XSS
IDOR |
Intigriti |
Ladecruze (@ladecruze) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1857 | A technique to semi-automatically find vulnerabilities in WordPress plugins |
XSS
SQL injection
Open redirect
CSRF |
NA |
kazet (@kazet1234) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1854 | Solving DOM XSS Puzzles |
DOM XSS |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1850 | What Bypassing Razer%27s DOM-based XSS Patch Can Teach Us |
DOM XSS |
Razer |
EdOverflow (@EdOverflow) |
Bug Bounty | 2022-02-05 | 2023-06-13 |
1843 | What I Found on Sony Vulnerability Disclosure Program |
Information disclosure
Lack of rate limiting
Open redirect
IDOR
XSS |
Sony |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-02-07 | 2023-06-13 |
1840 | SQL Injection, Reflected XSS and Information Disclosure in one subdomain in just 10 minutes |
SQL injection
XSS
Information disclosure |
NA |
Mahmoud Hamed (@7odamo_) |
Bug Bounty | 2022-02-08 | 2023-06-13 |