2569 | Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub |
Missing authentication
Forced browsing |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2568 | Exploiting Activity in medium android app |
Insecure intent
Android |
Medium |
Raju kumar (@MrCyberwarrior) |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2534 | CSRF from which we can create a support ticket in Victim’s Account (500$) |
CSRF |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2533 | Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device (500$) |
Information disclosure |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2515 | Escalating SSRF to Accessing all user PII information by aws metadata |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-05-31 | 2023-06-13 |
2511 | Escalating SSRF to Accessing all user PII information by aws metadata |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-06-01 | 2023-06-13 |
2498 | How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-06-06 | 2023-06-13 |
2477 | How We Are Able To Hack Any Company By Sending Message – $20,000 Bounty [CVE-2021–34506] |
Universal XSS |
Microsoft |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2021-06-15 | 2023-06-13 |
2443 | Misconfigured $3 Bucket - A Semi Opened Environment |
AWS misconfiguration |
Redbull |
Yukesh Kumar (@3th1c_yuk1) |
Bug Bounty | 2021-06-27 | 2023-06-13 |
2397 | How I was able Find mass leaked AWS s3 bucket from js File |
AWS misconfiguration |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-07-20 | 2023-06-13 |
2325 | Finding multiple SSRF with aws metadata access on A BANK system |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2316 | Confirming any new Email Address bug in Facebook (Part-4) |
Rate limiting bypass |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2021-08-17 | 2023-06-13 |
2177 | Privilege Escalation to stored XSS |
Privilege escalation
HTTP response manipulation
Stored XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2021-10-01 | 2023-06-13 |
2101 | Unauthenticated Access To Cloud Portal — A 🚪 Without 🗝️ |
Authentication bypass |
NA |
Yukesh Kumar (@3th1c_yuk1) |
Bug Bounty | 2021-11-05 | 2023-06-13 |
2083 | Privilege Escalation, worth of €300 |
Broken Access Control
IDOR
Privilege escalation |
NA |
Hemant Kumar |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2010 | Exploiting S3 bucket with path folder to Access PII info of A BANK |
AWS misconfiguration
Information disclosure |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
1672 | Multiple Times I Hacked Duke University With RXSS Vulnerability!!! |
Reflected XSS |
Duke University |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-02 | 2023-06-13 |
1669 | Hacked Instagram Handle Of Samsung…. |
Broken link hijacking |
Samsung |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-03 | 2023-06-13 |
1665 | Hacked Nokia With Reflected Cross-site Scripting Vulnerability…. |
Reflected XSS |
Nokia |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-04 | 2023-06-13 |
1606 | Open Redirection into Bentley System |
XSS |
Bentley Systems |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1590 | Contact Point Deanonymization Vulnerability in Meta |
Information disclosure |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1472 | 500$ Account Takeover |
Account takeover
Information disclosure
HTTP response manipulation |
Xsolla |
Hemant Kumar |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1465 | Automating reflected XSS with burp-suite Intruder |
Reflected XSS |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1448 | Account Takeover by OTP bypass |
Information disclosure
Client-side enforcement of server-side security
OTP bypass
Account takeover |
NA |
Vaibhav Kumar Srivastava |
Bug Bounty | 2022-06-19 | 2023-06-13 |
1402 | ($$$) Origin ip to account takeover |
WAF bypass
Password reset
Host header injection
Account takeover |
NA |
Hemant Kumar |
Bug Bounty | 2022-07-02 | 2023-06-13 |