613 | Advanced CSRF Exploitation |
CSRF
Stored XSS |
NA |
Sandro Einfeldt |
Bug Bounty | 2023-01-07 | 2023-06-13 |
606 | Hacking Hackers for fun and profit |
Self-XSS
Blind XSS |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
590 | XSS using postMessage in Google Cloud Theia notebooks [Google VRP] |
XSS
postMessage |
Google |
Sreeram KL (@kl_sree) |
Bug Bounty | 2023-01-15 | 2023-06-13 |
581 | DOM-Based XSS for fun and profit $$$! | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
561 | CSRF + Stored XSS Leading to Full Account Takeover |
Stored XSS
CSRF
Account takeover |
NA |
Fares Walid (@SirBagoza) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
558 | Bypassing Cloudflare WAF: XSS via SQL Injection |
Reflected XSS
SQL injection
WAF bypass |
NA |
Uku Sõrmus |
Bug Bounty | 2023-01-21 | 2023-06-13 |
557 | How I found XSS on Admin Page without login! |
Reflected XSS |
NA |
Abdelrhman Allam (@sl4x0) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
556 | Reflected XSS Leads to 3,000$ Bug Bounty Rewards from Microsoft Forms |
Reflected XSS |
Microsoft |
Supakiad S. (@Supakiad_Mee) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
544 | MyBB <= 1.8.31: Remote Code Execution Chain |
RCE
SQL injection
Stored XSS |
MyBB |
Aleksey Solovev |
Bug Bounty | 2023-01-25 | 2023-06-13 |
541 | OpenEMR - Remote Code Execution in your Healthcare System |
RCE
XSS
LFI
Arbitrary file read
Security code review |
OpenEMR |
Dennis Brinkrolf (@DBrinkrolf) |
Bug Bounty | 2023-01-26 | 2023-06-13 |
528 | Blind XSS To SSRF |
Blind XSS
SSRF |
NA |
Akash c |
Bug Bounty | 2023-01-29 | 2023-06-13 |
527 | How I was able to find 4 Cross-site scripting (XSS) on vulnerability disclosure program ? |
XSS |
NA |
DrakenKun |
Bug Bounty | 2023-01-29 | 2023-06-13 |
514 | RCE in Avaya Aura Device Services |
RCE
Security code review
XSS
WebDAV |
Avaya |
Dylan Pindur |
Bug Bounty | 2023-02-01 | 2023-06-13 |
503 | Discovering 5 XSS Vulnerabilities In a Simple Way With Xssor.go |
Reflected XSS |
NA |
Fares Walid (@SirBagoza) |
Bug Bounty | 2023-02-02 | 2023-06-13 |
500 | Play with Google, Twitter, Apple, Dell |
XSS
HTML injection
IDOR
Information disclosure |
Google
Twitter
Apple
Dell |
rezaduty (@rezaduty) |
Bug Bounty | 2023-02-03 | 2023-06-13 |
498 | postMessage DOM XSS vulnerability in Gartner Peer Insights widget |
postMessage
DOM XSS |
Gartner
Gradle
LogRhythm
SentinelOne
Synopsys
Veeam
Vodafone
Black Kite
ReversingLabs
Tata Communications |
Justin Steven (@justinsteven) |
Bug Bounty | 2023-02-04 | 2023-06-13 |
497 | SSO Gadgets: Escalate (Self-)XSS to ATO |
SSO
OAuth
Account takeover
Self-XSS
Login CSRF |
NA |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2023-02-04 | 2023-06-13 |
494 | How we made $120k bug bounty in a year with good automation |
XSS
Security misconfiguration
Log4shell
Debug mode enabled |
NA |
Dawid Moczadło (@kannthu1) |
Bug Bounty | 2023-02-06 | 2023-06-13 |
489 | A zero day for the government’s “demo servers” and internal networks |
XSS |
NA |
fopwn |
Bug Bounty | 2023-02-06 | 2023-06-13 |
481 | Reflected XSS on Target with tough WAF ( WAF Bypass ) |
Reflected XSS
WAF bypass |
NA |
Eagle_92 |
Bug Bounty | 2023-02-08 | 2023-06-13 |
451 | Securing Open-Source Solutions: A Study of osTicket Vulnerabilities |
Stored XSS
Reflected XSS
SQL injection
Session fixation |
osTicket |
Miguel Correia |
Bug Bounty | 2023-02-14 | 2023-06-13 |
447 | XSS on The MOST Popular Movie Ticket website. |
XSS |
NA |
Tarang Parmar |
Bug Bounty | 2023-02-15 | 2023-06-13 |
435 | Hacking the Search Bar: The Story of Discovering and Reporting an XSS Vulnerability on Bing.com |
XSS |
Microsoft (Bing) |
Niraj Mahajan |
Bug Bounty | 2023-02-18 | 2023-06-13 |
431 | Reflected Cross Site Scripting (Awards 3500$ bounty) |
Reflected XSS |
Shopify |
ShuttlerTech |
Bug Bounty | 2023-02-20 | 2023-06-13 |