2624 | Auth Bypass in Google Workspace Real Time Collaboration |
Authentication bypass
Information disclosure |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2476 | Authentication Bypass | Easy P1 in 10 minutes |
Authentication bypass
Forced browsing |
NA |
Anirudh Makkar (@anirudhmakkar) |
Bug Bounty | 2021-06-16 | 2023-06-13 |
2389 | How I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology & Tools |
SSTI
SQL injection
Authentication bypass
Privilege escalation
Reflected XSS |
Meta / Facebook |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2021-07-23 | 2023-06-13 |
2375 | Information Disclosure to Account Takeover |
Information disclosure
OAuth
Account takeover
Authentication bypass |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-07-28 | 2023-06-13 |
2307 | MonkeyType.com Stored Cross-Site Scripting |
Stored XSS
Authentication bypass
IDOR |
MonkeyType.com |
Tyle Butler (@tbutler0x90) |
Bug Bounty | 2021-08-22 | 2023-06-13 |
2275 | Proxytoken: An Authentication Bypass In Microsoft Exchange Server |
Authentication bypass |
Microsoft |
Xuan Tuyen |
Bug Bounty | 2021-08-30 | 2023-06-13 |
2248 | How I can take over any user’s account with their mobile number |
Account takeover
OTP bypass
Authentication bypass |
NA |
Sushmitha Katikitala |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2246 | SSD Advisory – NETGEAR D7000 Authentication Bypass |
Authentication bypass |
Netgear |
- |
Bug Bounty | 2021-09-06 | 2023-06-13 |
2219 | This is why you shouldn’t trust your Federated Identity Provider |
OAuth
Account takeover
Authentication bypass |
NA |
Soufiane Habti (@wld_basha) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2200 | Super Admin panel without Credentials 😎 |
Authentication bypass |
NA |
Rizwan_siddiqui (@Rizwan_SiDdiqu1) |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2188 | Bypass of biometrics & password security functionality for Android |
Authentication bypass
Android |
CoinDCX |
Dheeraj Madhukar (@Dheerajmadhukar) |
Bug Bounty | 2021-09-27 | 2023-06-13 |
2171 | CVE-2021-43136 – FormaLMS – The evil default value that leads to Authentication Bypass |
Authentication bypass
Security code review |
Forma LMS |
Cristian Giustini |
Bug Bounty | 2021-10-05 | 2023-06-13 |
2118 | Unauthorized access to any user’s account. |
IDOR
Authentication bypass
Account takeover |
NA |
vikram naidu (@ImVikram7msd) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2101 | Unauthenticated Access To Cloud Portal — A 🚪 Without 🗝️ |
Authentication bypass |
NA |
Yukesh Kumar (@3th1c_yuk1) |
Bug Bounty | 2021-11-05 | 2023-06-13 |
2040 | NodeBB 1.18.4 - Remote Code Execution With One Shot |
RCE
XSS
Authentication bypass
Arbitrary file read |
NodeBB |
Sonar (@SonarSource) |
Bug Bounty | 2021-11-30 | 2023-06-13 |
2014 | Another Admin panel |
HTTP response manipulation
Authentication bypass |
NA |
Rizwan_siddiqui (@Rizwan_SiDdiqu1) |
Bug Bounty | 2021-12-08 | 2023-06-13 |
1996 | How I found the Authentication Bypass bug and Earn $$$$ |
Session expiration issue |
NA |
Thedarkwayg (@shadow_CLAY) |
Bug Bounty | 2021-12-15 | 2023-06-13 |
1985 | Blackbox Cookie Testing — How I Cracked The Admin’s Cookie |
Authentication bypass |
NA |
Saeed Balquizi |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1981 | How I found (P2) Broken Authentication with Zero Skill of Hacking |
Authentication bypass
Account takeover |
NA |
yoshi m lutfi (@yoshiahmadlutfi) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1973 | Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲 |
Authentication bypass
IDOR
Lack of rate limiting |
NA |
Anurag__Verma |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1949 | The Story Of How I Bypass SSO Login |
Authentication bypass |
NA |
zer0d |
Bug Bounty | 2022-01-02 | 2023-06-13 |
1917 | 120 Days of High Frequency Hunting |
SSRF
LFI
Information disclosure
Broken Access Control
Authentication bypass
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-15 | 2023-06-13 |
1904 | ZohOwned :: A Critical Authentication Bypass on Zoho ManageEngine Desktop Central |
Authentication bypass |
Zoho |
Steven Seeley (@steventseeley) |
Bug Bounty | 2022-01-20 | 2023-06-13 |
1888 | Auth Bypass in ADOdb CVE-2021-3850 |
Authentication bypass |
NA |
Emmet Leah |
Bug Bounty | 2022-01-26 | 2023-06-13 |
1847 | Auth Bypass in com.google.android.googlequicksearchbox |
Authentication bypass |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-02-06 | 2023-06-13 |