1608 | Exploiting a File Upload Vulnerability — A Directory Traversal Attack |
Unrestricted file upload
Path traversal |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-04-20 | 2023-06-13 |
1594 | Bypassing WAF for $2222 |
WAF bypass
Path traversal |
NA |
Divyansh Sharma |
Bug Bounty | 2022-04-27 | 2023-06-13 |
1538 | Leaking Your GitHub Repositories With Snyk Code |
Path traversal
Broken Access Control |
NA |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-05-20 | 2023-06-13 |
1528 | Breaking Reverse Proxy Parser Logic |
Path traversal |
NA |
Blake Jacobs (@z0idsec) |
Bug Bounty | 2022-05-22 | 2023-06-13 |
1511 | External Authentication bypass in ingress-nginx |
Path traversal
Authentication bypass |
Kubernetes |
Niemiec Marcin (@xvnpw) |
Bug Bounty | 2022-05-29 | 2023-06-13 |
1417 | Unrar Path Traversal Vulnerability affects Zimbra Mail |
Path traversal
Arbitrary file write
RCE |
Zimbra |
Sonar (@SonarSource) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1416 | Pwning ManageEngine — From PoC to Exploit: A deep dive into CVE-2020–11531 and CVE-2020–11532 |
Path traversal
RCE
Authentication bypass |
Zoho |
Erik Wynter (@WynterErik) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1339 | Write-up: BlogEngine .NET - 0day Discovery |
Path traversal
XXE |
BlogEngine .NET |
Jake McCallum (@0xLanks) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1297 | Arris / Arris-variant DSL/Fiber router critical vulnerability exposure |
Path traversal
Memory corruption |
ARRIS |
Derek Abdine (@dabdine) |
Bug Bounty | 2022-07-29 | 2023-06-13 |
1284 | (ZOHO) Manage Engine Desktop Central – SQL Injection / Arbitrary File Write |
SQL injection
Arbitrary file write
Path traversal |
Zoho |
Tom Ellson (@tde_sec) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1256 | How I earned a $6000 bug bounty from Cloudflare |
Path traversal |
Cloudflare |
ANDRI |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1251 | Mining Node.js Vulnerabilities via Object Dependence Graph and Query |
RCE
OS command injection
Prototype pollution
Path traversal |
NA |
Song Li |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1219 | We discovered major vulnerabilities in Control Web Panel. Here’s how we found them. |
Path traversal
RCE
Weak crypto
Password reset
Account takeover |
Centos Web Panel (CWP) |
Immersive Labs (@immersivelabs) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1191 | Useless path traversals in Zyxel admin interface (CVE-2022-2030) |
Path traversal |
Zyxel |
Maurizio Agazzini (@0x696e6f6465) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1183 | Oracle SBC: Multiple Security Vulnerabilities Leading to Unauthorized Access and Denial of Service |
IDOR
Path traversal
DoS |
Oracle |
Harold Zang |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1105 | QUEST KACE Desktop Authority Pre-Auth Remote Code Execution (CVE-2021-44031) |
RCE
Path traversal |
Quest |
Tom Ellson (@tde_sec) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1100 | Riding The Inforail To Exploit Ivanti Avalanche Part 2 |
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
1053 | Tarfile: Exploiting the World With a 15-Year-Old Vulnerability |
Path traversal |
Python |
Kasimir Schulz (@Abraxus7331) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1050 | Tarfile: Exploiting the World With a 15-Year-Old Vulnerability |
Path traversal |
Python |
Kasimir Schulz (@Abraxus7331) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1021 | The forgotten IPFS vulnerabilities |
Web3 hacking
Path traversal
CORS misconfiguration
HTML injection |
Filecoin Security |
tintinweb |
Bug Bounty | 2022-09-28 | 2023-06-13 |
974 | Breaking Parser Logic: Gain Access To NGINX Plus API — Read/Write Upstreams. |
Path traversal |
NA |
Cyberlix (@cyberlixio) |
Bug Bounty | 2022-10-12 | 2023-06-13 |
960 | It’s the Little Things : Breaking an AI |
Path traversal |
NA |
Debangshu Kundu (@debangshu_kundu) |
Bug Bounty | 2022-10-13 | 2023-06-13 |
950 | Toner Deaf – Printing your next persistence (Hexacon 2022) |
Path traversal
Arbitrary file write
RCE
Printer hacking |
Lexmark |
Alex Plaskett (@alexjplaskett) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
941 | Remote Code Execution in Melis Platform |
RCE
Path traversal
Insecure deserialization
Security code review |
Melis Platform |
Karim El Ouerghemmi |
Bug Bounty | 2022-10-18 | 2023-06-13 |
890 | CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities |
RCE
Phar deserialization
Reflected XSS
XPATH injection
Path traversal
LFI |
Juniper |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-10-28 | 2023-06-13 |