4570 | Responsible disclosure: retrieving a user%27s private Facebook friends. |
Logic flaw
Authorization flaw
Information disclosure |
Meta / Facebook |
Riccardo Padovani (@rpadovani93) |
Bug Bounty | 2018-09-23 | 2023-06-13 |
4562 | Just another tale of severe bugs on a private program. |
Open redirect
SSRF
IDOR
Logic flaw |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4560 | Hacking the Subway Android app |
Logic flaw
Authorization flaw |
Subway |
Wesley Gahr (@wesley_gahr) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4553 | Facebook Bug Bounty: Email Id, Phone Number Can be exposed Through Business Manager |
Logic flaw
Information disclosure |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2018-10-03 | 2023-06-13 |
4552 | Exploiting an unknown vulnerability |
Logic flaw
Payment tampering |
NA |
Abhishek Bundela (@abhibundela) |
Bug Bounty | 2018-10-03 | 2023-06-13 |
4549 | GoogleMeetRoulette: Joining random meetings |
Bruteforce
Logic flaw |
Google |
Martin Vigo (@martin_vigo) |
Bug Bounty | 2018-10-04 | 2023-06-13 |
4541 | Make any Unit in Facebook Groups Undeletable |
Logic flaw
IDOR
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4537 | Payment bypass |
Payment bypass
Logic flaw |
NA |
Pratik Yadav (@PratikY9967) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4526 | Security teams Internal attachments can be exported via "Export as .zip" feature on HackerOne |
Logic flaw |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2018-10-17 | 2023-06-13 |
4522 | A possibility of Account Takeover in Medium |
Account takeover
Logic flaw |
Medium |
Prashant Kumar (@notsoshant) |
Bug Bounty | 2018-10-20 | 2023-06-13 |
4521 | Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature |
Logic flaw |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2018-10-22 | 2023-06-13 |
4502 | Bypass HackerOne 2FA requirement and reporter blacklist |
Logic flaw
MFA bypass
Authentication flaw |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2018-10-31 | 2023-06-13 |
4475 | Facebook Vulnerability: Hiding from the view of Business Admin in the Business Manager |
Logic flaw
Authorization flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2018-11-15 | 2023-06-13 |
4466 | Bypassing “How I hacked Google’s bug tracking system itself for $15,600 in bounties.” |
Logic flaw |
Google |
Gopal Singh (@gopalsinghcse) |
Bug Bounty | 2018-11-17 | 2023-06-13 |
4456 | Bypassing Scratch Cards On Google Pay |
Logic flaw |
Google |
Pratheesh P Narayanan |
Bug Bounty | 2018-11-22 | 2023-06-13 |
4440 | Remotely Hijacking Zoom Clients |
Logic flaw |
Zoom |
David Wells |
Bug Bounty | 2018-12-03 | 2023-06-13 |
4431 | Facebook WhiteHat: Able to access group plan even after leaving the group |
Authorization flaw
Logic flaw |
Meta / Facebook |
Family guy |
Bug Bounty | 2018-12-06 | 2023-06-13 |
4415 | Chaining Two Vulnerabilities to Break Facebook Appointment Times For the Second Time |
Logic flaw
Application-level DoS |
Meta / Facebook |
Max Pasqua |
Bug Bounty | 2018-12-14 | 2023-06-13 |
4414 | Unremovable Tags In Facebook Page Reviews |
Logic flaw |
Meta / Facebook |
Max Pasqua |
Bug Bounty | 2018-12-14 | 2023-06-13 |
4363 | Facebook Vulnerability: Unremovable facebook group admin |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4341 | How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc) |
Logic flaw
Authentication flaw |
Google
Microsoft
Meta / Facebook |
Luke Berner |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4340 | Facebook Change Product Availability as a PageAnalyst |
Logic flaw
Authorization flaw |
Meta / Facebook |
onehackzero |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4338 | Misconfiguration-Whatsapp Messenger |
Logic flaw |
Meta / Facebook |
Pratheesh P Narayanan |
Bug Bounty | 2019-01-26 | 2023-06-13 |
4329 | $7.5k Google Cloud Platform organization issue |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2019-01-30 | 2023-06-13 |
4288 | How I Registered Multiple Accounts in PrivateInternetAccess VPN Service for FREE |
Logic flaw |
PrivateInternetAccess VPN |
Spade |
Bug Bounty | 2019-02-20 | 2023-06-13 |