702 | Not usual CSP bypass case |
Unrestricted file upload
XSS
CSP bypass |
NA |
Karol Mazurek |
Bug Bounty | 2022-12-12 | 2023-06-13 |
691 | CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution |
Websockets
XSS
RCE
Arbitrary file write
Path traversal |
OnlyOffice |
Iain Wallace (@strawp) |
Bug Bounty | 2022-12-14 | 2023-06-13 |
689 | FlowscreenComponents Basepack, Version 3.0.7 Advisory |
XSS
Security code review |
UnofficialSF |
Matthew Rutledge |
Bug Bounty | 2022-12-15 | 2023-06-13 |
688 | Missing Bricks: Finding Security Holes in LEGO APIs |
XSS
XXE |
LEGO |
Shiran Yodev |
Bug Bounty | 2022-12-15 | 2023-06-13 |
686 | Param Hunting to Injections |
HTML injection
XSS |
NA |
302 Found |
Bug Bounty | 2022-12-16 | 2023-06-13 |
685 | CVE-2022-42710: A journey through XXE to Stored-XSS |
Stored XSS
XXE
Security code review |
Linear |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-12-16 | 2023-06-13 |
682 | I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS |
Stored XSS
Self-XSS |
Zoom |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2022-12-17 | 2023-06-13 |
679 | How I was able to steal users credentials via Swagger UI DOM-XSS |
DOM XSS
Old components with known vulnerabilities |
NA |
Mohamed Reda (@M0x0101) |
Bug Bounty | 2022-12-18 | 2023-06-13 |
678 | Better Make Sure Your Password Manager Is Secure |
Hardcoded credentials
XSS
Cryptographic issues
Authorization flaw
Authentication bypass |
Click Studios |
kuekerino (@kuekerino) |
Bug Bounty | 2022-12-19 | 2023-06-13 |
676 | How I found my first XSS on a Bug Bounty Program |
XSS |
Coinbase |
Vikas Anand (@kingcoolvikas) |
Bug Bounty | 2022-12-20 | 2023-06-13 |
666 | Zero Click To Account Takeover (IDOR + XSS) |
IDOR
XSS
Account takeover |
NA |
Arman (@M7arm4n) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
657 | $350 XSS in 15 minutes |
DOM XSS
JSONP |
NA |
Anton (@therceman) |
Bug Bounty | 2022-12-23 | 2023-06-13 |
656 | Microsoft bug reports lead to ranking on Microsoft MSRC Quarterly Leaderboard (Q3 2022) |
XSS |
Microsoft |
Supakiad S. (@Supakiad_Mee) |
Bug Bounty | 2022-12-23 | 2023-06-13 |
649 | Uncovering a Bug I Found in Outlook: How Could an Account Has Been Compromised? |
XSS |
Microsoft |
Cem Onat Karagun |
Bug Bounty | 2022-12-26 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
645 | Stored XSS vulnerability in Microsoft booking |
Stored XSS
CSP bypass |
Microsoft |
Mrtechghost |
Bug Bounty | 2022-12-27 | 2023-06-13 |
637 | How I got a Bug At Apple that lead’s to takeover accounts of any user who view my profile |
XSS
Account takeover |
Apple |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-12-29 | 2023-06-13 |
636 | Exploring the World of ESI Injection |
ESI injection
WAF bypass
XSS |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2022-12-29 | 2023-06-13 |
633 | How I took over an admin panel and got $500 |
Blind XSS
Account takeover |
NA |
Muhammed Mubarak |
Bug Bounty | 2023-01-01 | 2023-06-13 |
629 | An amazing way to turn a xss into an ATO |
XSS
Account takeover |
NA |
Naka |
Bug Bounty | 2023-01-02 | 2023-06-13 |
628 | Web-Cache Poisoning $$$? Worth it? |
Web cache poisoning
XSS |
NA |
Yaseen Zubair |
Bug Bounty | 2023-01-02 | 2023-06-13 |
627 | Exploiting thousands of Domains for XSS |
XSS |
GoDaddy |
Kailash (@Corrupted_brain) |
Bug Bounty | 2023-01-02 | 2023-06-13 |
623 | Vue JS Reflected XSS |
Reflected XSS
Blind XSS
CORS misconfiguration
UI redressing |
NA |
sid0krypt (@Siddhar07949650) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
622 | Fetch Diversion |
DOM XSS |
NA |
Nicolas Christin (@acut3hack) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
617 | Blind XSS in Email Field; 1000$ bounty |
Blind XSS |
NA |
Yaseen Zubair |
Bug Bounty | 2023-01-05 | 2023-06-13 |