1389 | stored XSS and stored HTML Injection in United Nations Website |
XSS
HTML injection |
United Nations |
Ahmed Hassan |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1387 | Flash XSS in ajax.googleapis.com |
XSS |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1381 | How we have pwned Root-Me in 2022 |
XSS
CSRF
RCE |
SPIP |
SpawnZii (@SpawnZii) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1375 | Leveraging the SQL Injection to Execute the XSS by Evading CSP |
CSP bypass
SQL injection
XSS |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1370 | Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP |
XSS
CSP bypass
HTML injection |
Microsoft |
Numan Turle (@numanturle) |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1369 | From Open Redirect to Reflected XSS manually |
Open redirect
Reflected XSS |
NA |
Rodric |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1366 | Tableau Server Leaks Sensitive Information From Reflected XSS |
Reflected XSS |
Salesforce |
Simon Bouchard (@SimTwisted) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1355 | CRLF to Account takeover (chaining bugs) |
CRLF injection
XSS
Account takeover |
NA |
MoSec (@moe1n1) |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1354 | Going beyond Alert with XSS |
XSS
Account takeover |
NA |
pipsh |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1351 | CVE-2022–35909 / CVE-2022–35910, Incorrect Access Control and XSS Stored to Jellyfin |
Broken Access Control
XSS |
jellyfin |
Dan Barros |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1328 | WordPress Transposh: Exploiting a Blind SQL Injection via XSS - RCE Security |
SQL injection
XSS
Account takeover |
WordPress |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1306 | Google XSS |
XSS |
Google |
NDevTK (@ndevtk) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1300 | Researching Open Source apps for XSS to RCE flaws |
XSS
RCE |
NA |
Aleksey Solovev |
Bug Bounty | 2022-07-28 | 2023-06-13 |
1295 | Discord Desktop - Remote Code Execution |
RCE
XSS
Sandbox bypass
CSP bypass |
Discord |
s1r1us (@s1r1u5_) |
Bug Bounty | 2022-07-29 | 2023-06-13 |
1291 | How I get Full Account Takeover via stealing action’s login form | XSS |
XSS
Account takeover |
NA |
Mohamed Tarek (@timooon107) |
Bug Bounty | 2022-08-01 | 2023-06-13 |
1288 | Stored XSS to Account Takeover : Going beyond document.cookie | Stealing Session Data from IndexedDB |
Stored XSS
Account takeover |
NA |
Syed Mushfik Hasan Tahsin (@SMHTahsin33) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1283 | XSS in Gmail%27s Amp4Email |
XSS |
Google |
Adi "Adico" Cohen (@wir3less2) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1280 | Came looking for SSRF and found XSS |
XSS
WAF bypass |
NA |
Ibrahim Radi (@ibraradi9) |
Bug Bounty | 2022-08-04 | 2023-06-13 |
1269 | Stored XSS in app.gitbook.com |
Stored XSS |
GitBook |
Mohammad Alfin Hidayatullah (@Alpinbrainsec) |
Bug Bounty | 2022-08-08 | 2023-06-13 |
1266 | Bypassed Cloudflare’s Web Application Firewall (WAF) |
XSS
HTML injection
WAF bypass |
NA |
Ansh Vaid (@anshvaid4) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1259 | Defeat the HttpOnly flag to achieve Account Takeover | RXSS |
Reflected XSS
Account takeover |
NA |
Mohamed Tarek (@timooon107) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1248 | My Experience on Hacking the Dutch Government |
XSS
Open redirect
CSRF
Account takeover |
Dutch Government |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1239 | How I found an XSS vulnerability via using emojis |
XSS |
Swisscom |
Patrik Fabian |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1237 | DOM Cross-Site Scripting Via postMessage in AnnounceKit |
DOM XSS |
Announcekit |
Lorenzo Stella (@lorenzostella) |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1233 | Escalating Open Redirect to XSS |
Open redirect
XSS |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-08-13 | 2023-06-13 |