1538 | Leaking Your GitHub Repositories With Snyk Code |
Path traversal
Broken Access Control |
NA |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-05-20 | 2023-06-13 |
1440 | We were vulnerable - how a security company could have vulns |
Broken Access Control
Authorization flaw
Information disclosure |
Volkis |
Soman Verma |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1433 | An Out Of Scope domain Leads To a Critical Bug[$1500] |
Authorization flaw
Broken Access Control |
NA |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2022-06-24 | 2023-06-13 |
1420 | Access control worth $2000 (everyone missed this IDOR+Access control between two admins.) |
IDOR
Broken Access Control |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1400 | We Hacked Larksuite For 1 month and Here is what we found |
XSS
IDOR
Privilege escalation
Broken Access Control
CSRF
40x bypass |
Lark Technologies |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-07-04 | 2023-06-13 |
1351 | CVE-2022–35909 / CVE-2022–35910, Incorrect Access Control and XSS Stored to Jellyfin |
Broken Access Control
XSS |
jellyfin |
Dan Barros |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1321 | Technical Advisory – Multiple vulnerabilities in Nuki smart locks (CVE-2022-32509, CVE-2022-32504, CVE-2022-32502, CVE-2022-32507, CVE-2022-32503, CVE-2022-32510, CVE-2022-32506, CVE-2022-32508, CVE-2022-32505) |
Memory corruption
DoS
Broken Access Control
Sensitive Information Sent Over an Unencrypted Channel |
Nuki |
Daniel Romero (@daniel_rome) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1058 | Securing Developer Tools: OneDev Remote Code Execution |
RCE
SSRF
Broken Access Control
Container escape |
OneDev |
Paul Gerste |
Bug Bounty | 2022-09-20 | 2023-06-13 |
980 | [Hacking Banks] Broken Access Control Vulnerability in Banking application [PART I] |
Broken Access Control
Android |
NA |
Abdelhak Kharroubi |
Bug Bounty | 2022-10-10 | 2023-06-13 |
971 | Broken Access Control leads to full team takeover and privilege escalation |
Broken Access Control
Privilege escalation |
NA |
Abdelhameed Ghazy (@El3Etraa1) |
Bug Bounty | 2022-10-12 | 2023-06-13 |
918 | Finding Multiple Security Issues on Agorapulse |
Log4shell
RCE
Information disclosure
Broken Access Control
Privilege escalation |
Agorapulse |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
917 | Atlassian Jira Align, Version 10.107.4 Advisory |
SSRF
Broken Access Control
Privilege escalation |
Atlassian |
Jacob Shafer (@fibbot) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
876 | Improper Access Control — My Third Finding on Hackerone! |
HTML injection
Broken Access Control |
NA |
mehedishakeel (@mehedishakeel) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
769 | Automating Unsolicited Richard Pics; Pwning 60,000 Digital Picture Frames |
IDOR
Broken Access Control
Android
IoT |
Ourphoto |
Nick M (@1oopho1e) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
763 | The Untold SendBird Misconfigurations |
Broken Access Control |
SendBird |
LTiDi (@dunglt140150) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
761 | Broken access control + misconfiguration = Beautiful privilege escalation |
Broken Access Control
Privilege escalation |
NA |
Hossam Mesbah (@m359ah) |
Bug Bounty | 2022-11-28 | 2023-06-13 |
699 | AWS ECR Public Vulnerability |
Cloud
Privilege escalation
Broken Access Control |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2022-12-13 | 2023-06-13 |
695 | Privilege escalation leads to deleting other user’s account and company Workspace [Access Control] |
Privilege escalation
Broken Access Control |
NA |
Pratik Gaikwad |
Bug Bounty | 2022-12-14 | 2023-06-13 |
605 | Full Team Takeover |
Broken Access Control
Logic flaw |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
602 | Full Team Takeover |
Account takeover
Broken Access Control |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
586 | Full Account Take Over by very simple trick. |
Account takeover
Broken Access Control |
NA |
XeRox01 (@xerox0x1) |
Bug Bounty | 2023-01-16 | 2023-06-13 |
560 | Vulnerabilities in ManageEngine ADSelfService Plus 6.1 build 6117 |
RCE
OS command injection
Broken Access Control |
Zoho (ManageEngine) |
Antoine Cervoise (@acervoise) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
467 | We Hacked GitHub for a Month: Here’s What We Found |
Pre-account takeover
Broken Access Control
Email verification bypass
Logic flaw |
GitHub |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
432 | [1500$ Worth — Slack] vulnerability, bypass invite accept process |
Broken Access Control
Logic flaw |
Slack |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-02-20 | 2023-06-13 |
430 | Exposing 185M+ Indians’ Personal Information and much more |
Broken Access Control
IDOR
Information disclosure |
Aadhaar
CERT-In |
Robin Justin (@_robinjustin_) |
Bug Bounty | 2023-02-20 | 2023-06-13 |