269 | Exploiting prototype pollution in Node without the filesystem |
Server-side prototype pollution
RCE |
NA |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2023-03-23 | 2023-06-13 |
268 | Joomla! CVE-2023-23752 to Code Execution |
Broken Access Control
RCE |
Joomla! |
Jacob Baines (@Junior_Baines) |
Bug Bounty | 2023-03-23 | 2023-06-13 |
267 | Hacking AI: System and Cloud Takeover via MLflow Exploit |
LFI
RFI
RCE |
MLflow |
Dan McInerney (@DanHMcInerney) |
Bug Bounty | 2023-03-25 | 2023-06-13 |
265 | How I escalated default credentials to Remote Code Execution |
Default credentials
RCE |
NA |
Pawan Chhabria (@heybenchmarkkk) |
Bug Bounty | 2023-03-26 | 2023-06-13 |
254 | It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS |
RCE
Stored XSS
Security code review |
LibreNMS |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
251 | Riding the Azure Service Bus (Relay) into Power Platform |
RCE
Cross-tenant vulnerability
Cloud
Insecure deserialization |
Microsoft (Azure) |
Nick Landers (@monoxgas) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
249 | Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack |
RCE
CI/CD
Supply chain attack |
Microsoft (Azure Pipelines) |
Nadav Noy |
Bug Bounty | 2023-03-30 | 2023-06-13 |
248 | Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383) |
RCE
XSS
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-03-30 | 2023-06-13 |
240 | Finding RCE in NodeJS templating engine %27Eta%27 - CVE-2022-25967 |
RCE
Server-side prototype pollution
Security code review |
Eta |
Rayhan Ahmed Niloy (@Rayhan0x01) |
Bug Bounty | 2023-04-01 | 2023-06-13 |
233 | CyberGhostVPN - the story of finding MITM, RCE, LPE in the Linux client |
RCE
MiTM
Local Privilege Escalation |
CyberGhost |
mmmds |
Bug Bounty | 2023-04-03 | 2023-06-13 |
231 | Pentah0wnage: Pre-Auth RCE in Pentaho Business Analytics Server |
RCE
SSTI
Authorization bypass
Groovy scripting |
Hitachi Vantara (Pentaho) |
Harry Withington |
Bug Bounty | 2023-04-04 | 2023-06-13 |
210 | From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys |
Cloud
Privilege escalation |
Microsoft (Azure) |
Roi Nisimi (@) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
209 | Shell in the Ghost: Ghostscript CVE-2023-28879 writeup |
Buffer Overflow
Memory corruption
RCE |
Ghostscript |
sigabrt9 (@sigabrt9) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
208 | Pretalx Vulnerabilities: How to get accepted at every conference |
Arbitrary file read
Arbitrary file write
RCE
Security code review |
Pretalx |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
205 | Losing control over Schneider%27s EcoStruxure Control Expert |
RCE
Path traversal
Security code review |
Schneider Electric |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
199 | How I got RCE in + 10 websites… |
RCE
Security misconfiguration |
NA |
m4cddr (@m4cddr) |
Bug Bounty | 2023-04-13 | 2023-06-13 |
198 | Remote Code Execution Vulnerability in Google They Are Not Willing To Fix |
Dependency confusion
RCE |
Google |
Giraffe Security |
Bug Bounty | 2023-04-14 | 2023-06-13 |
192 | (CVE-2023-2017) Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension |
SSTI
RCE
Security code review |
Shopware |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
190 | Multiple Critical Vulnerabilities In Strapi Versions <=4.7.1 |
Authentication bypass
SSTI
RCE
Amazon cognito misconfiguration
Information disclosure |
Strapi |
GhostCcamm (@GhostCcamm) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
176 | CVE-2022-29844: A Classic Buffer Overflow On The Western Digital My Cloud Pro Series PR4100 |
Buffer Overflow
Memory corruption
RCE |
Western Digital |
Luca Moro (@johncool__) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
166 | Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers |
Salesforce
Security misconfiguration
Broken Access Control |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2023-04-21 | 2023-06-13 |
160 | Vocera Report Server Pwnage |
RCE
Arbitrary file upload
Path traversal
Zip Slip attack |
Stryker |
b0yd (@rwincey) |
Bug Bounty | 2023-04-24 | 2023-06-13 |
158 | CVE-2023-27524: Insecure Default Configuration in Apache Superset Leads to Remote Code Execution |
RCE
Default Flask Secret Key
Hardcoded credentials |
Apache Superset |
Naveen Sunkavally |
Bug Bounty | 2023-04-25 | 2023-06-13 |
149 | Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707) |
RCE
Insecure deserialization |
Microsoft (Exchange) |
Nguyễn Tiến Giang (@testanull) |
Bug Bounty | 2023-04-28 | 2023-06-13 |