770 | A Real World Example Of Classic Remote Command Execution (RCE) |
OS command injection
XSS
RCE |
NA |
Bhashit Pandya (@x30r_) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
745 | Command Injection in Asus M25 NAS |
OS command injection
Source code disclosure |
Asus |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
660 | Puckungfu: A NETGEAR WAN Command Injection |
OS command injection
Security code review |
Netgear |
McCaulay Hudson (@_mccaulay) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
620 | Cacti: Unauthenticated Remote Code Execution |
RCE
Authentication bypass
OS command injection
Security code review |
Cacti |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
596 | SSH key injection in Google Cloud Compute Engine [Google VRP] |
OS command injection
RCE |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-12 | 2023-06-13 |
560 | Vulnerabilities in ManageEngine ADSelfService Plus 6.1 build 6117 |
RCE
OS command injection
Broken Access Control |
Zoho (ManageEngine) |
Antoine Cervoise (@acervoise) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
542 | Kamailio’s exec module considered harmful |
OS command injection
SIP |
Kamailio |
Ali Norouzi |
Bug Bounty | 2023-01-26 | 2023-06-13 |
437 | Facebook bug: A Journey from Code Execution to S3 Data Leak |
RCE
OS command injection |
Meta / Facebook |
Bipin Jitiya (@win3zz) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
390 | The Tale of a Command Injection by Changing the Logo |
RCE
OS command injection
Unrestricted file upload
Directory listing
HTTP response manipulation |
NA |
0xrz (@omidxrz) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
385 | $10.000 bounty for exposed .git to RCE |
.git folder disclosure
RCE
OS command injection |
NA |
Lev Shmelev |
Bug Bounty | 2023-02-27 | 2023-06-13 |
359 | CS-Cart PDF Plugin Unauthenticated Command Injection |
RCE
OS command injection
Security code review |
CS-Cart |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
332 | PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 |
RCE
OS command injection
Security code review |
Netgear |
Zion Basque (@mahal0z) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
328 | The Silent Spy Among Us: Modern Attacks Against Smart Intercoms |
IoT
OS command injection
Missing authentication
MiTM
SIP |
Akuvox |
Claroty%27s Team82 (@Claroty) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
314 | The story of how I was able to chain SSRF with Command Injection Vulnerability |
SSRF
OS command injection
RCE |
NA |
Raj Qureshi (@RajQureshi9) |
Bug Bounty | 2023-03-12 | 2023-06-13 |
299 | Backend Parameter Injection --> RCE |
RCE
HTTP parameter pollution
OS command injection |
NA |
Austin (@systemdumb) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
139 | Azure Devops CICD Pipelines - Command Injection With Parameters, Variables And A Discussion On Runner Hijacking |
CI/CD
OS command injection
RCE |
Microsoft (Azure DevOps Pipelines) |
Sana Oshika (@bigshika) |
Bug Bounty | 2023-05-01 | 2023-06-13 |
120 | Bullied by Bugcrowd over Kape CyberGhost disclosure |
Local Privilege Escalation
OS command injection
Security code review |
Kape (CyberGhost) |
Ceri Coburn (@_ethicalchaos_) |
Bug Bounty | 2023-05-05 | 2023-06-13 |
91 | Triple Threat: Breaking Teltonika Routers Three Ways |
IoT
RCE
OS command injection
SSRF
XSS |
Teltonika |
Roni Gavrilov |
Bug Bounty | 2023-05-15 | 2023-06-13 |
87 | Unauthenticated Remote Command Execution in Multiple WAGO Products |
RCE
OS command injection
Security code review |
WAGO |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2023-05-16 | 2023-06-13 |
86 | Hardcore RCE via directory name for $3.000 |
RCE
OS command injection
Security code review |
NA |
Lev Shmelev |
Bug Bounty | 2023-05-16 | 2023-06-13 |
75 | Blind OS Command Injection via Activation Request |
OS command injection |
NA |
Arumusutakimu (@arumusutakimu) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
74 | Blind OS Command Injection via Activation Request |
Memory corruption
Buffer Overflow
Out-of-bounds Read |
VMware |
Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
41 | an offensive look at docker desktop extensions |
OS command injection
Container security |
Docker |
Leon Jacobs (@leonjza) |
Bug Bounty | 2023-05-30 | 2023-06-13 |
22 | SSD Advisory – Roundcube MarkAsJunk RCE |
RCE
OS command injection
Security code review |
Roundcube |
Selim Enes Karaduman (@Enesdex) |
Bug Bounty | 2023-06-06 | 2023-06-13 |