871 | Get Blind XSS within 5 Minutes — $100 |
Blind XSS |
NA |
Narayanan M |
Bug Bounty | 2022-11-03 | 2023-06-13 |
868 | Case of Admin Bypass for RCE, XSS, and Information Disclosure |
RCE
Unrestricted file upload
Stored XSS
Information disclosure |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
864 | PENTEST TALES: EXIF Data Manipulation |
Unrestricted file upload
Stored XSS |
NA |
Armand Jasharaj |
Bug Bounty | 2022-11-05 | 2023-06-13 |
836 | Finding Reflected XSS In A Strange Way |
XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-11-11 | 2023-06-13 |
829 | Winning QR with DOM-Based XSS | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-11-15 | 2023-06-13 |
817 | Got Another XSS using Double Encoding |
XSS |
NA |
ag3n7 |
Bug Bounty | 2022-11-17 | 2023-06-13 |
813 | Bypassing XSS filters using Double Encoding |
XSS
WAF bypass |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
806 | Remediation Archeology — Finding and Decoding an Ancient XSS |
XSS |
NA |
Bend Theory (@bendtheory) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
805 | Russian roulette XSS |
Blind XSS |
NA |
Splintersec (@splint3rsec) |
Bug Bounty | 2022-11-19 | 2023-06-13 |
803 | How i found 29 stored XSS in modern framework |
Stored XSS |
NA |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
794 | Interesting Stored XSS via meta data |
Stored XSS |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2022-11-22 | 2023-06-13 |
791 | CVE-2021-40662 Chamilo LMS 1.11.14 RCE |
Stored XSS
CSRF
RCE |
Chamilo LMS |
Febin |
Bug Bounty | 2021-11-23 | 2023-06-13 |
790 | XSS Vulnerability Found in ConnectWise Remote Access Platform With Great Potential For Misuse by Scammers |
Stored XSS |
ConnectWise |
Nati Tal |
Bug Bounty | 2022-11-23 | 2023-06-13 |
788 | How I get +10 SQLi and +30 XSS via Automation Tool |
SQL injection
XSS |
NA |
Mahmoud Attia (@0xElkot) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
773 | WebView XSS, account takeover |
Webview XSS
Android
Account takeover
Improper Export of Android Application Components |
NA |
shafou |
Bug Bounty | 2022-11-26 | 2023-06-13 |
772 | A great weekend hack(worth $8k) |
SQL injection
IDOR
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
770 | A Real World Example Of Classic Remote Command Execution (RCE) |
OS command injection
XSS
RCE |
NA |
Bhashit Pandya (@x30r_) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
764 | Multiple Vulnerabilities found in Airtel Android Application |
Arbitrary Code Execution
URL validation bypass
Symlink attack
XSS
Android
Webview |
Airtel
Google |
Gaurang Bhatnagar (@hax0rgb) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
759 | Cross-Site Scripting in CodeIgniter version 3.1.13 |
Reflected XSS
Security code review |
CodeIgniter |
Antoine Cervoise |
Bug Bounty | 2022-11-29 | 2023-06-13 |
754 | Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video |
Stored XSS |
TikTok |
Aidil Arief |
Bug Bounty | 2022-11-30 | 2023-06-13 |
751 | XSS on account.leagueoflegends.com via easyXDM [2016] |
XSS
postMessage |
Riot Games |
Luke Young (@TheBoredEng) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
742 | Multiple Vulnerabilities in Proxmox VE & Proxmox Mail Gateway |
XSS
CRLF injection
SSRF
LFI
Local Privilege Escalation
Arbitrary file read |
Proxmox |
JianTao Li (@cursered) |
Bug Bounty | 2022-12-02 | 2023-06-13 |
736 | A $$$ worth of cookies! | Reflected DOM-Based XSS | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-12-03 | 2023-06-13 |
712 | Automate Cross-Site Scripting (XSS) exploitation with unusal events and Burp Intruder |
XSS
WAF bypass |
NA |
Riccardo Malatesta (@seeu_inspace) |
Bug Bounty | 2022-12-10 | 2023-06-13 |
705 | How “I hacked the Dutch government and got the lousy t-shirt” |
XSS |
Dutch Government |
IamDEAD |
Bug Bounty | 2022-12-11 | 2023-06-13 |