2407 | How i was able to bypass Cloudflare for XSS! |
XSS |
NA |
hosein vita (@HoseinVita) |
Bug Bounty | 2021-07-16 | 2023-06-13 |
2405 | Remote code execution in cdnjs of Cloudflare |
RCE
Path traversal |
Cloudflare |
RyotaK (@ryotkak) |
Bug Bounty | 2021-07-16 | 2023-06-13 |
2385 | Easy Bounty With Exposed Buckets & Blobs |
Cloud storage misconfiguration |
NA |
mr.d0x (@mrd0x) |
Bug Bounty | 2021-07-26 | 2023-06-13 |
2291 | Reflective XSS via search box [Bypassing Cloudflare WAF]. |
Reflected XSS |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2285 | SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection |
WAF bypass
SSRF
SQL injection |
NA |
Caesar Evan Santoso |
Bug Bounty | 2021-08-28 | 2023-06-13 |
2257 | Google Cloud Build — under the hood |
gRPC |
Google |
Imre Rad (@ImreRad) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2235 | Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances |
Container takeover
Container escape
Privilege escalation
Cloud |
Microsoft |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2021-09-09 | 2023-06-13 |
2226 | Hacking CloudKit - How I accidentally deleted your Apple Shortcuts |
Logic flaw |
Apple |
Frans Rosén (@fransrosen) |
Bug Bounty | 2021-09-13 | 2023-06-13 |
2186 | Zero-Day: Hijacking iCloud Credentials with Apple Airtags (Stored XSS) |
Stored XSS |
Apple |
Bobby Rauch / Bobbyr |
Bug Bounty | 2021-09-28 | 2023-06-13 |
2181 | How I found bug on Google Cloud |
OTP bypass |
Google |
Anuragbhoir11 |
Bug Bounty | 2021-09-30 | 2023-06-13 |
2101 | Unauthenticated Access To Cloud Portal — A 🚪 Without 🗝️ |
Authentication bypass |
NA |
Yukesh Kumar (@3th1c_yuk1) |
Bug Bounty | 2021-11-05 | 2023-06-13 |
2069 | Write Up – Apple N/A: PII Information, Full Contact List, Main Phone No. And Main Icloud Email Extracted; Bug Patched: Arbitrary Local File Read Via Zip File And Symlinks On Ios Files App. |
Arbitrary file read |
Apple |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2064 | How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud |
Information disclosure
Authentication flaw |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
1976 | Cache Poisoning at Scale |
Web cache poisoning |
GitHub
GitLab
HackerOne
Shopify
Cloudflare |
Youstin (@iustinBB) |
Bug Bounty | 2021-12-23 | 2023-06-13 |
1964 | Remote Code Execution in Google Cloud Dataflow |
RCE |
Google |
Mike Brancato (@meatballninja) |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1961 | Google Cloud Shell XSS |
XSS |
Google |
NDevTK (@ndevtk) |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1958 | Bypassing Identity-Aware Proxy - Google Cloud Vulnerability |
Authorization flaw
Token leak
OAuth |
Google |
SebLu |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1954 | Fixing the Unfixable: Story of a Google Cloud SSRF |
SSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1881 | Command Injection in Google Cloud Shell |
RCE
OS command injection |
Google |
Ademar Nowasky Junior |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1845 | Insecure Bootstrap Process in Oracle Cloud CLI |
Supply chain attack |
Oracle |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2022-02-06 | 2023-06-13 |
1819 | Advisory: Western Digital My Cloud Pro Series PR4100 RCE |
RCE
OS command injection |
Western Digital |
Quentin Kaiser (@QKaiser) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1816 | Hunting for bugs in VMware: View Planner and vRealize Business for Cloud |
RCE |
VMware |
Mikhail Klyuchnikov (@__Mn1__) |
Bug Bounty | 2022-02-15 | 2023-06-13 |
1799 | Bypassing Cloudflare’s WAF! |
XSS
WAF bypass |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2022-02-19 | 2023-06-13 |
1785 | Piercing the Cloud Armor - The 8KB bypass in Google Cloud Platform WAF |
WAF bypass |
Google |
Kloudle (@Kloudleinc) |
Bug Bounty | 2022-02-24 | 2023-06-13 |
1781 | Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager |
Authentication bypass
RCE
SSRF
Path traversal |
VMware |
Egor Dimitrenko (@elk0kc) |
Bug Bounty | 2022-02-25 | 2023-06-13 |