4525 | Add comment on a private Oculus Developer bug report |
IDOR
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-18 | 2023-06-13 |
4511 | How Misconfigured API leaked user private information? |
IDOR
Authorization flaw |
NA |
Yeasir Arafat |
Bug Bounty | 2018-10-26 | 2023-06-13 |
4475 | Facebook Vulnerability: Hiding from the view of Business Admin in the Business Manager |
Logic flaw
Authorization flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2018-11-15 | 2023-06-13 |
4473 | Creating unauthorized comments on Facebook Live Stream! |
Privilege escalation
Authorization flaw |
Meta / Facebook |
Binit Ghimire (@WHOISbinit) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4431 | Facebook WhiteHat: Able to access group plan even after leaving the group |
Authorization flaw
Logic flaw |
Meta / Facebook |
Family guy |
Bug Bounty | 2018-12-06 | 2023-06-13 |
4423 | How I could have stolen your photos from Google |
Parameter tampering
Authorization flaw
IDOR |
Google |
Gergő Turcsányi (@GergoTurcsanyi) |
Bug Bounty | 2018-12-11 | 2023-06-13 |
4403 | Exploiting Two Endpoints to get Account Takeover |
Authorization flaw
Privilege escalation |
NA |
Hritik Sharma |
Bug Bounty | 2018-12-19 | 2023-06-13 |
4397 | Client side validation strikes again: PIN code bypass ! |
Client-side enforcement of server-side security
Authentication bypass
Authorization flaw |
Netflix
Linxo |
Davy (@RandoriSec) |
Bug Bounty | 2018-12-22 | 2023-06-13 |
4394 | Unauthenticated user can upload an attachment at HackerOne |
Authorization flaw |
HackerOne |
Ahamed Morad (@Modam3r5) |
Bug Bounty | 2018-12-24 | 2023-06-13 |
4388 | Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket |
Unrestricted file upload
Authorization flaw |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-12-30 | 2023-06-13 |
4386 | Bypassing Access Control in a Program on Hackerone !! |
Authorization flaw |
HackerOne |
Sahil Tikoo (@viperbluff) |
Bug Bounty | 2018-12-30 | 2023-06-13 |
4384 | A Curious Case From Little To Complete Email Verification Bypass |
Email verification bypass
Authorization flaw |
NA |
Megaman (@N0_M3ga_Hacks) |
Bug Bounty | 2019-01-01 | 2023-06-13 |
4376 | Facebook Android Application |
Authorization flaw |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2019-01-05 | 2023-06-13 |
4369 | Facebook PageAnalyst Could Add oneself as Moderator on Group |
Authorization flaw |
Meta / Facebook |
onehackzero |
Bug Bounty | 2019-01-11 | 2023-06-13 |
4340 | Facebook Change Product Availability as a PageAnalyst |
Logic flaw
Authorization flaw |
Meta / Facebook |
onehackzero |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4336 | A short tale of Account verification bypass |
Email verification bypass
Authorization flaw |
NA |
Satyendra Kumar |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4334 | Unsecured access to personal data of a million Leo Express users |
Authorization flaw
XSS |
Leo Express |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2019-01-29 | 2023-06-13 |
4332 | Guest blog: Eray Mitrani - Hacking isn’t an exact science |
Authorization flaw |
NA |
Eray Mitrani (@ErayMitrani) |
Bug Bounty | 2019-01-29 | 2023-06-13 |
4328 | How I found a simple bug in Facebook without any Test |
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2019-01-31 | 2023-06-13 |
4284 | Exploiting Google Calendars |
Authorization flaw
Information disclosure |
Uber
Shopify
Netflix |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2019-02-22 | 2023-06-13 |
4282 | Download any organisation Data — S3 amazonaws Misconfiguration |
Authorization flaw |
NA |
Chand Singh (@Chand_42) |
Bug Bounty | 2019-02-22 | 2023-06-13 |
4267 | Fixed : Register any email address on Facebook Account |
Authorization flaw |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4260 | Inserting malware into anyone’s Google Earth Projects Archive |
IDOR
XSS
Authorization flaw |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2019-03-10 | 2023-06-13 |
4240 | Slack announcement-only channel post restriction bypass |
Authorization flaw
Logic flaw |
Slack |
Rodney Beede |
Bug Bounty | 2019-03-20 | 2023-06-13 |
4202 | The Outlook Winner is Dash |
Authorization flaw |
Microsoft |
marcan2020 (@marcan2020) |
Bug Bounty | 2019-04-15 | 2023-06-13 |