4585 | Persistent Cross-Site Scripting on redacted worth $2,000 |
Stored XSS |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-09-15 | 2023-06-13 |
4584 | IDOR User Account Takeover By Connecting My Facebook Account with victims Account |
IDOR |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4583 | User Account takeover in India’s largest digital business company |
Account takeover
OTP bypass |
NA |
Minali Arora (@AroraMinali) |
Bug Bounty | 2018-09-16 | 2023-06-13 |
4582 | XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites |
XSS |
Google |
Randy Westergren (@RandyWestergren) |
Bug Bounty | 2018-09-17 | 2023-06-13 |
4581 | Reflected XSS at Philips.com |
Reflected XSS |
Philips |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-09-17 | 2023-06-13 |
4580 | Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution ) |
LFI
Unrestricted file upload
RCE |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4579 | Facebook $750 Reward for a Simple Bug |
Authentication bypass
Logic flaw |
Meta / Facebook |
Aman Shahid (@amansmughal) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4578 | How i bypassed AKAMAI KONA WAF , XSS in overstock.com ! |
XSS |
Overstock.com |
Oktavandi (@0ktavandi) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4577 | Bypassing Authentication Using Javascript Debugger. |
Authentication bypass |
NA |
Mohit Dabas (@mohitdabas08) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4576 | Local file inclusion at IKEA.com |
LFI |
Ikea |
Jonathan Bouman (@JonathanBouman) |
Bug Bounty | 2018-09-19 | 2023-06-13 |
4575 | Shopify Athena Bug |
Authorization flaw
Information disclosure |
Shopify |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-09-20 | 2023-06-13 |
4574 | Another XSS in Google Colaboratory |
XSS |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2018-09-20 | 2023-06-13 |
4573 | Bypassing Firebase authorization to create custom goo.gl subdomains |
Logic flaw
IDOR |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
4572 | R-XSS -> CSRF bypass to account takeover/ |
Reflected XSS
CSRF |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
4571 | How I XSS’ed Uber and Bypassed CSP |
Reflected XSS |
Uber |
Efkan (@mefkansec) |
Bug Bounty | 2018-09-22 | 2023-06-13 |
4570 | Responsible disclosure: retrieving a user%27s private Facebook friends. |
Logic flaw
Authorization flaw
Information disclosure |
Meta / Facebook |
Riccardo Padovani (@rpadovani93) |
Bug Bounty | 2018-09-23 | 2023-06-13 |
4569 | Subdomain Takeover via Unsecured S3 Bucket Connected to the Website |
Subdomain takeover |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-09-24 | 2023-06-13 |
4568 | Weaponizing XSS Attacking Internal System |
Blind XSS |
NA |
Rahul R |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4567 | [XSS] survey.dropbox.com |
XSS |
Dropbox |
Kumar |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4566 | How I got $4000 from Visma for RCE |
RCE |
Visma |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4565 | Arbitrary File Read in one of the largest CRMs |
LFI |
NA |
Richard Clifford (@MantisSTS) |
Bug Bounty | 2018-09-26 | 2023-06-13 |
4564 | Thick Client — Attacking databases the fun/easy way |
Thick client
Credentials sent over unencrypted channel |
NA |
Richard Clifford (@MantisSTS) |
Bug Bounty | 2018-09-26 | 2023-06-13 |
4563 | #BugBounty — From finding Jenkins instance to Command Execution.Secure your Jenkins Instance! |
RCE
Exposed Jenkins instance |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-09-27 | 2023-06-13 |
4562 | Just another tale of severe bugs on a private program. |
Open redirect
SSRF
IDOR
Logic flaw |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4561 | IDOR, Content Spoofing and Url Redirection via unsubscribe email in Confluent |
IDOR
Content spoofing
Open redirect |
Confluent |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2018-09-28 | 2023-06-13 |