4090 | Facebook Vulnerability: Unremovable Co-Host in facebook group events |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-06-19 | 2023-06-13 |
4058 | Facebook Vulnerability: Unremovable Co-Host in facebook page events |
Logic flaw
DoS |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-07-04 | 2023-06-13 |
3994 | No Rate limiting eligible for bounty ? |
Lack of rate limiting |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2019-08-03 | 2023-06-13 |
3970 | How I was able to earn 1000$ with just 10 minutes of bug bounty? |
Password reset |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2019-08-17 | 2023-06-13 |
3953 | How i was able to exploit the same endpoint 2 times ( multiple xss & open Redirection on 10 subdomain) |
XSS
Open redirect |
Sanity.io |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2019-08-26 | 2023-06-13 |
3911 | How I able to Takeover 10 subdomains in a Private Program ? |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-09-20 | 2023-06-13 |
3892 | How a double-free bug in WhatsApp turns to RCE |
Memory corruption
RCE
Android |
Meta / Facebook |
Awakened |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3877 | How I was able to bypass OTP code requirement in Razer [The story of a critical bug] |
OTP bypass |
Razer |
Ananda Dhakal (@dhakal_ananda) |
Bug Bounty | 2019-10-16 | 2023-06-13 |
3866 | Responsible denial of service with web cache poisoning |
DoS
Web cache poisoning |
Tesla
HackerOne
Deliveroo
Bitbucket
Paypal
Meta / Facebook
Twitter |
James Kettle (@albinowax) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3858 | Cross Site Request Forgery Critical Exploitable IN Infected Site? |
CSRF |
NA |
Hossam Mesbah |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3827 | This is How I was able to hunt a rare bug in a private program |
Missing authentication
Privilege escalation |
NA |
Abida Fahd |
Bug Bounty | 2019-11-18 | 2023-06-13 |
3816 | Disable Any Unconfirmed Account in Facebook |
Bruteforce |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2019-11-21 | 2023-06-13 |
3808 | Getting access to disabled/hidden features with the help of Burpsuite Match and Replace settings |
Authorization flaw |
NA |
Johns Simon (@Johnssimon22) |
Bug Bounty | 2019-11-27 | 2023-06-13 |
3789 | AirDoS: Remotely render any nearby iPhone or iPad unusable |
DoS |
Apple |
Kishan Bagaria (@KishanBagaria) |
Bug Bounty | 2019-12-10 | 2023-06-13 |
3782 | How I was able to find a logical bug on Instagram? |
Logic flaw |
Meta / Facebook |
Jabir Khan (@Jabirkhan0x0) |
Bug Bounty | 2019-12-13 | 2023-06-13 |
3721 | The trouble with Microsoft’s Troubleshooters |
RCE
MiTM |
Microsoft |
Imre Rad (@ImreRad) |
Bug Bounty | 2020-01-15 | 2023-06-13 |
3709 | How I was able to take over any users account with host header injection |
Host header injection |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3696 | How I was able to takeover the company’s LinkedIn Page |
Broken link hijacking |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-01-29 | 2023-06-13 |
3688 | Responsible Disclosure: Breaking out of a Sandboxed Editor to perform RCE |
RCE |
HackerEarth |
Jatin Dhankhar (@jatindhankhar_) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3676 | How Inspect Element Got me a Bounty |
Client-side enforcement of server-side security |
NA |
Aditya Soni (@hetroublemakr) |
Bug Bounty | 2020-02-06 | 2023-06-13 |
3619 | Vulnerable design leads to personal data leakage- yet another case of an inter-application vulnerability… |
Logic flaw |
NA |
Marcin Szydlowski (@SecurityKsl) |
Bug Bounty | 2020-03-09 | 2023-06-13 |
3615 | How I was able to bypass the current password? |
Account takeover
CSRF |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3598 | How I was able to verify any contact number for my account? |
OTP bypass
MFA bypass |
NA |
Paras Arora (@parasarora06) |
Bug Bounty | 2020-03-17 | 2023-06-13 |
3541 | How was i able to find privilege escalation. |
IDOR
Authorization flaw |
NA |
Akshar Tank (@Akshar__tank) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3506 | Private Dashboards were accessible by other Admins in Analytics Dashboard |
Authorization flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2020-05-02 | 2023-06-13 |