583 | Unauthenticated Configuration Export in Multiple WAGO Products |
Path traversal
Security code review |
WAGO |
ONEKEY (@onekey_sec) |
Bug Bounty | 2023-02-16 | 2023-06-13 |
548 | Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI |
RCE
Authentication bypass
Security code review
JWT |
Yellowfin BI |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2023-01-24 | 2023-06-13 |
541 | OpenEMR - Remote Code Execution in your Healthcare System |
RCE
XSS
LFI
Arbitrary file read
Security code review |
OpenEMR |
Dennis Brinkrolf (@DBrinkrolf) |
Bug Bounty | 2023-01-26 | 2023-06-13 |
536 | PHP Development Server <= 7.4.21 - Remote Source Disclosure |
Source code disclosure
Information disclosure
Security code review |
PHP |
Rahul Maini (@iamnoooob) |
Bug Bounty | 2023-01-28 | 2023-06-13 |
535 | CVE-2022-44789 |
Memory corruption
Use-After-Free
RCE
Security code review |
Artifex MuJS |
Alvin Ng (@alngpwn) |
Bug Bounty | 2023-01-28 | 2023-06-13 |
532 | Froxlor v2.0.6 Remote Command Execution (CVE-2023-0315) |
RCE
Arbitrary file write
SSTI
Security code review |
Froxlor |
Askar (@mohammadaskar2) |
Bug Bounty | 2023-01-29 | 2023-06-13 |
521 | Unserializable, But Unreachable: Remote Code Execution On vBulletin |
RCE
Insecure deserialization
Security code review |
vBulletin |
Charles Fol (@cfreal_) |
Bug Bounty | 2023-01-31 | 2023-06-13 |
519 | Remote Command Execution in binwalk |
RCE
Path traversal
Security code review |
ReFirm Labs (binwalk)
ubi_reader
jefferson
yaffshiv |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2023-01-31 | 2023-06-13 |
514 | RCE in Avaya Aura Device Services |
RCE
Security code review
XSS
WebDAV |
Avaya |
Dylan Pindur |
Bug Bounty | 2023-02-01 | 2023-06-13 |
512 | ImageMagick: The hidden vulnerability behind your online images |
Application-level DoS
Arbitrary file read
Security code review |
ImageMagick |
Bryan Gonzalez |
Bug Bounty | 2023-02-01 | 2023-06-13 |
508 | Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails |
RCE
Security code review
Missing authentication
Insecure deserialization |
IBM |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2023-02-02 | 2023-06-13 |
502 | WEEKEND DESTROYER - RCE in Western Digital PR4100 NAS |
RCE
Hardcoded credentials
Privilege escalation
Cryptographic issues
Security code review |
Western Digital |
Pedro Ribeiro (@pedrib1337) |
Bug Bounty | 2023-02-02 | 2023-06-13 |
499 | Authentication Bypass in Izanami Docker image 1.10.22 CVE-2023-22495 |
Authentication bypass
JWT
Security code review
Container security |
Izanami |
Raphaël Lob |
Bug Bounty | 2023-02-03 | 2023-06-13 |
493 | GoAnywhere MFT - A Forgotten Bug |
Insecure deserialization
Security code review |
Fortra (GoAnywhere) |
Florian Hauser (@frycos) |
Bug Bounty | 2023-02-06 | 2023-06-13 |
492 | Apache SCXML Remote Code Execution |
RCE
Security code review |
Apache SCXML |
pyn3rd (@pyn3rd) |
Bug Bounty | 2023-02-06 | 2023-06-13 |
485 | [CVE-2023-22855] Kardex MLOG - Insecure path join to RCE via SSTI |
RCE
SSTI
Security code review |
NA |
Patrick Hener (@C1sc01) |
Bug Bounty | 2023-02-07 | 2023-06-13 |
479 | Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization |
Insecure deserialization
RCE
Security code review |
Inductive Automation Ignition |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
463 | XXE with Auto-Update in install4j |
XXE
Security code review |
Prosys OPC |
Florian Hauser (@frycos) |
Bug Bounty | 2023-02-12 | 2023-06-13 |
424 | ClamAV Critical Patch Review |
RCE
Memory corruption
Buffer Overflow
XXE
Security code review |
ClamAV |
ONEKEY (@onekey_sec) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
414 | Vulnerability write-up - "Dangerous assumptions" |
Prototype pollution
SQL injection
Security code review |
DIVD |
Thomas Rinsma (@thomasrinsma) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
413 | Unauthenticated RCE in Goanywhere |
Insecure deserialization
RCE
Security code review |
Fortra (GoAnywhere) |
Youssef Muhammad (@yosef0x1) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
398 | draw.io CVEs |
SSRF
OAuth
Open redirect
Token leak
Security code review |
draw.io |
@caioluders |
Bug Bounty | 2023-02-24 | 2023-06-13 |
383 | VMware Workspace One Access |
RCE
Java Beans
Security code review |
VMware |
Steven Seeley (@steventseeley) |
Bug Bounty | 2023-02-27 | 2023-06-13 |
378 | CVE-2022-38108: RCE In Solarwinds Network Performance Monitor |
Insecure deserialization
RCE
Security code review |
SolarWinds |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
359 | CS-Cart PDF Plugin Unauthenticated Command Injection |
RCE
OS command injection
Security code review |
CS-Cart |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-03-03 | 2023-06-13 |