Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
143Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera RCE Unrestricted file upload Path traversal Security code review Oracle (Opera) Shubham Shah (@infosec_au) Bug Bounty2023-04-302023-06-13
139Azure Devops CICD Pipelines - Command Injection With Parameters, Variables And A Discussion On Runner Hijacking CI/CD OS command injection RCE Microsoft (Azure DevOps Pipelines) Sana Oshika (@bigshika) Bug Bounty2023-05-012023-06-13
138Apache Solr 8.3.1 RCE from exposed administration interface RCE Unrestricted file upload XSLT injection Path traversal Apache Solr Nicolas Brunner Bug Bounty2023-05-012023-06-13
135SSD Advisory – KerioControl Remote Code Execution RCE TAR path traversal GFI Software (KerioControl) Simon Janz Bug Bounty2023-05-022023-06-13
134CVE-2023-28231: RCE In The Microsoft Windows DHCPv6 Service RCE Buffer Overflow Memory corruption Microsoft (Windows) Guy Lederfein (@glederfein) Bug Bounty2023-05-022023-06-13
130When you%27re so bored, you start debugging someone else%27s code: bug hunting in a random Cloud-Native project SSTI RCE Foreman ONSEC.io Research Team Bug Bounty2023-05-032023-06-13
114How a simple Directory Listing leads to PII Data Leakage, Remote Code Execution and many more vulnerabilities on a HR management subdomain RCE Unrestricted file upload Stored XSS Information disclosure Directory listing NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-05-072023-06-13
112Sorting Your Way to Stolen Passwords Bruteforce Cryptographic issues NA Nightbane (@Nightbanes) Bug Bounty2023-05-082023-06-13
110A deep-dive on Pluck CMS vulnerability CVE-2023-25828 Unrestricted file upload RCE Security code review Pluck CMS Matthew Hogg Bug Bounty2023-05-082023-06-13
109PwnAssistant - Controlling /home%27s Via A Home Assistant RCE Authentication bypass RCE Security code review IoT Home Assistant elttam (@elttam) Bug Bounty2023-05-092023-06-13
106RCE due to Dependency Confusion — $5000 bounty! Dependency confusion RCE NA Chevon Phillip (@ChevonPhillip) Bug Bounty2023-05-102023-06-13
104Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3 RCE Authorization bypass Security code review Sitecore Dylan Pindur Bug Bounty2023-05-102023-06-13
103What is kong & why we’re relying on it RCE Sandbox escape Authentication bypass Hardcoded credentials Broken Access Control Privilege escalation JWT Konga Laluka (@TheLaluka) Bug Bounty2023-05-102023-06-13
96CS:GO: From Zero to 0-day Game hacking RCE Memory corruption Arbitrary file download Arbitrary file write DLL Hijacking Privilege Escalation Valve (CS:GO) Felipe Bug Bounty2023-05-132023-06-13
94Pimcore: One click, two security vulnerabilities Path traversal SQL injection Arbitrary file write RCE Security code review Pimcore Yaniv Nizry (@YNizry) Bug Bounty2023-05-152023-06-13
91Triple Threat: Breaking Teltonika Routers Three Ways IoT RCE OS command injection SSRF XSS Teltonika Roni Gavrilov Bug Bounty2023-05-152023-06-13
87Unauthenticated Remote Command Execution in Multiple WAGO Products RCE OS command injection Security code review WAGO Quentin Kaiser (@QKaiser) Bug Bounty2023-05-162023-06-13
86Hardcore RCE via directory name for $3.000 RCE OS command injection Security code review NA Lev Shmelev Bug Bounty2023-05-162023-06-13
64Red team: Journey from RCE to have total control of cloud infrastructure RCE SSTI Container escape Kubernetes Components with known vulnerabilities CI/CD NA Quang Vo (@mr_r3bot) Bug Bounty2023-05-222023-06-13
53Exploiting The Sonos One Speaker Three Different Ways: A Pwn2Own Toronto Highlight Memory corruption RCE Out-of-bounds Read Sonos The ZDI Research Team (@thezdi) Bug Bounty2023-05-252023-06-13
52Exploring Three Remote Code Execution Vulnerabilities in RPC Runtime RCE MS-RPC Integer overflow Memory corruption Microsoft (Windows) Ben Barnea (@nachoskrnl) Bug Bounty2023-05-262023-06-13
49Anonymised Penetration Test Report Internal pentest RCE ADCS Active Directory Kerberos DHCPv6 LLMNR NA Volkis (@VolkisAU) Bug Bounty2023-05-282023-06-13
48The 30000$ Bounty Affair. RCE Missing authentication Exposed Jenkins instance NA Gokulsspace (@GokTest) Bug Bounty2023-05-282023-06-13
44VSCode Remote Code Execution advisory RCE Thick client Local Privilege Escalation Microsoft VSCode) Ammar Askar Bug Bounty2023-05-302023-06-13
40Kramer VIA GO² – Multiple issues RCE SQL injection Arbitrary file upload Arbitrary file read Kramer Jim Rush (@JimSRush) Bug Bounty2023-05-312023-06-13