243 | Unveiling the Secrets: My Journey of Hacking Google’s OSS |
CSRF
Self-XSS |
Google |
7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) |
Bug Bounty | 2023-03-31 | 2023-06-13 |
238 | Let’s Hack Citizens Bank |
XSS |
Citizens Bank |
Arman (@M7arm4n) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
234 | Blind XSS via SMS Support Chat — $1100 Bug Bounty! |
Blind XSS
Chatbot |
NA |
Chevon Phillip (@ChevonPhillip) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
225 | Exploiting insecure exception logging |
Blind XSS |
NA |
Bogdan Calin |
Bug Bounty | 2023-04-05 | 2023-06-13 |
220 | A web security story from 2008: silently securing JSON.parse |
Parsing issue
XSS
Arbitrary Code Execution |
JSON.parse |
Mike Samuel (@mvsamuel) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
218 | Stored Cross-Site Scripting (XSS) in Zimbra version 8.8.15_GA_4059 CVE-2022-41348 |
Stored XSS |
Zimbra |
Guillaume Jacques |
Bug Bounty | 2023-04-07 | 2023-06-13 |
214 | A successful prototype pollution chained to a DOM XSS |
Prototype pollution
DOM XSS |
NA |
Allam Rachid (@blank_cold) |
Bug Bounty | 2023-04-10 | 2023-06-13 |
211 | CVE-2023-1767 - Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score |
Stored XSS
Markdown XSS
Supply chain attack |
Snyk |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2023-04-10 | 2023-06-13 |
204 | How ChatGPT helped me find a bug |
XSS
File upload |
NA |
Abhishekgk |
Bug Bounty | 2023-04-11 | 2023-06-13 |
195 | How do I get cross site scripting(“xss”) in “Nokia” |
XSS |
Nokia |
EL Sayed Mohammed (@ElsayedMo77amed) |
Bug Bounty | 2023-04-16 | 2023-06-13 |
185 | Popping Tags: Exploiting Template Injections in PRTG Network Monitor |
Reflected XSS
CSTI |
Paessler |
Peter Szot |
Bug Bounty | 2023-04-18 | 2023-06-13 |
175 | Uncovering a Critical Vulnerability: My Journey of Discovering CVE-2021–31589, a Reflected XSS in LinkedIn |
Components with known vulnerabilities
Reflected XSS |
LinkedIn |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
174 | Turning Vulnerability into Bounty: How CVE-2020–17453 XSS Earned Me a $500 Bounty |
Components with known vulnerabilities
XSS |
NA |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
170 | Turning Vulnerability into Bounty: How CVE-2020–17453 XSS Earned Me a $500 Bounty |
Components with known vulnerabilities
XSS |
NA |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
159 | Odoo: Get your Content Type right, or else! |
XSS
Security code review |
Odoo |
Dennis Brinkrolf (@DBrinkrolf) |
Bug Bounty | 2023-04-24 | 2023-06-13 |
153 | Finding XSS in a million websites (cPanel CVE-2023-29489) |
Reflected XSS
Security code review |
cPanel |
Shubham Shah (@infosec_au) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
141 | Bug Bounty Writeup: Stored XSS Vulnerability WAF Bypass |
Stored XSS
WAF bypass |
NA |
Rafael Silva "lopseg" |
Bug Bounty | 2023-05-01 | 2023-06-13 |
122 | A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF… |
postMessage
JSONP
DOM XSS
CORS misconfiguration
CSRF
WAF bypass |
NA |
Julien Cretel (@jub0bs) |
Bug Bounty | 2023-05-05 | 2023-06-13 |
116 | Size matters! When capital letters introduce vulnerabilities |
XSS |
Microsoft |
Mario Stathakopoulos |
Bug Bounty | 2023-05-06 | 2023-06-13 |
115 | How I discovered XSS via triple URL encode |
XSS
WAF bypass |
NA |
Muhammed Mubarak |
Bug Bounty | 2023-05-07 | 2023-06-13 |
114 | How a simple Directory Listing leads to PII Data Leakage, Remote Code Execution and many more vulnerabilities on a HR management subdomain |
RCE
Unrestricted file upload
Stored XSS
Information disclosure
Directory listing |
NA |
Aayush Vishnoi (@AayushVishnoi10) |
Bug Bounty | 2023-05-07 | 2023-06-13 |
108 | Discovery of an XSS on Opera |
XSS |
Opera |
Arman (@M7arm4n) |
Bug Bounty | 2023-05-10 | 2023-06-13 |
91 | Triple Threat: Breaking Teltonika Routers Three Ways |
IoT
RCE
OS command injection
SSRF
XSS |
Teltonika |
Roni Gavrilov |
Bug Bounty | 2023-05-15 | 2023-06-13 |
73 | Official extension spoofing attacks: when trusted add-ons are not so trusted |
Extension spoofing
Account takeover
XSS |
NA |
Yesenia Trejo (@Yess_2021xD) |
Bug Bounty | 2023-05-19 | 2023-06-13 |
57 | how I found a tricky XSS |
XSS |
NA |
Ziad Ali |
Bug Bounty | 2023-05-24 | 2023-06-13 |