382 | Abusing Maven’s pom.xml |
RCE |
Apache Maven |
Gianluca Baldi (@0x_nope) |
Bug Bounty | 2023-02-27 | 2023-06-13 |
381 | My First Un-Expected $$$$ Digit Bounty for an Un-Expected Vulnerability |
Lack of rate limiting
Bruteforce |
NA |
Shobhit Mehta |
Bug Bounty | 2023-02-28 | 2023-06-13 |
379 | A student%27s dream: hacking (then fixing) Gradescope%27s autograder |
RCE |
Gradescope |
Aditya Saligrama (@saligrama_a) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
378 | CVE-2022-38108: RCE In Solarwinds Network Performance Monitor |
Insecure deserialization
RCE
Security code review |
SolarWinds |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
377 | Empowering weak primitives: file truncation to code execution with Git |
Argument injection
RCE |
NA |
Thomas Chauchefoin (@swapgs) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
376 | A New Vector For “Dirty” Arbitrary File Write to RCE |
Arbitrary file write
RCE |
NA |
Maxence Schmitt (@maxenceschmitt) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
359 | CS-Cart PDF Plugin Unauthenticated Command Injection |
RCE
OS command injection
Security code review |
CS-Cart |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
346 | Accessing to Data Sources of any Facebook Business account via IDOR in GraphQL |
IDOR
GraphQL |
Meta / Facebook |
Mukund Bhuva (@MukundBhuva) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
343 | Manipulating Encrypted Traffic for Manual and Automation |
Client-side encryption bypass
Bruteforce |
NA |
Sourav Kalal (@Ano_F_) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
342 | Remote Stealth Brute-force of Oracle Database Passwords |
Bruteforce
Information disclosure
Authentication bypass
Components with known vulnerabilities |
NA |
Viktor Markopoulos |
Bug Bounty | 2023-03-06 | 2023-06-13 |
337 | WordPress BuddyForms Plugin — Unauthenticated Insecure Deserialization (CVE-2023–26326) |
Insecure deserialization
Security code review
RCE |
NA |
Joshua Martinelle (@J0_mart) |
Bug Bounty | 2023-03-07 | 2023-06-13 |
332 | PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 |
RCE
OS command injection
Security code review |
Netgear |
Zion Basque (@mahal0z) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
330 | CorePlague: Severe Vulnerabilities in Jenkins Server Lead to RCE |
RCE
XSS
Security code review |
Jenkins |
Ilay Goldman (@GoldmanIlay) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
327 | EJS - Server Side Prototype Pollution gadgets to RCE |
Server-side prototype pollution
RCE
Security code review |
Node.js third-party modules (EJS) |
Mizu (@kevin_mizu) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
318 | CVE-2022-36413 Unauthorized Reset Password of Zoho ManageEngine ADSelfService Plus |
Password reset
OTP bruteforce
Account takeover
Authentication bypass |
Zoho (ManageEngine) |
Sky |
Bug Bounty | 2023-03-10 | 2023-06-13 |
314 | The story of how I was able to chain SSRF with Command Injection Vulnerability |
SSRF
OS command injection
RCE |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2023-03-12 | 2023-06-13 |
303 | Producing a POC for CVE-2022-42475 (Fortinet RCE) |
Memory corruption
RCE
Integer overflow
Heap overflow |
Fortinet |
Alain Mowat (@plopz0r) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
299 | Backend Parameter Injection --> RCE |
RCE
HTTP parameter pollution
OS command injection |
NA |
Austin (@systemdumb) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
296 | Emotional Rollercoaster: A Unique Case Study of Bypassing Antivirus and Firewall by Abusing PostgreSQL |
RCE
Old components with known vulnerabilities |
NA |
Yousef Amery (@YousefAmery) |
Bug Bounty | 2023-03-15 | 2023-06-13 |
286 | Remote code execution in BIRT Viewer ≤ 4.12.0 (CVE-2023-0100) |
RCE
RFI
URL validation bypass
Security code review |
Eclipse Foundation |
Louis Wolfers (@TG91aXMK) |
Bug Bounty | 2023-03-17 | 2023-06-13 |
282 | SSTI leads to RCE on PyroCMS |
SSTI
RCE |
PyroCMS |
cupc4k3 |
Bug Bounty | 2023-03-20 | 2023-06-13 |
281 | JMX Exploitation Revisited |
RCE
JMX |
NA |
Markus Wulftange (@mwulftange) |
Bug Bounty | 2023-03-20 | 2023-06-13 |
271 | Finding Initial Access on a real life Penetration Test |
Old components with known vulnerabilities
Internal pentest
RCE |
NA |
Warren Butterworth (@w88ugs) |
Bug Bounty | 2023-03-23 | 2023-06-13 |
270 | Escalating Privileges with Azure Function Apps |
Privilege escalation
Cloud
Container escape
RCE |
Microsoft (Azure) |
Karl Fosaaen (@kfosaaen) |
Bug Bounty | 2023-03-23 | 2023-06-13 |