868 | Case of Admin Bypass for RCE, XSS, and Information Disclosure |
RCE
Unrestricted file upload
Stored XSS
Information disclosure |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
867 | How I hacked into a Cambridge’s server and got appreciation letter. |
Unrestricted file upload
RCE |
Cambridge |
Prathamrajgor |
Bug Bounty | 2022-11-04 | 2023-06-13 |
864 | PENTEST TALES: EXIF Data Manipulation |
Unrestricted file upload
Stored XSS |
NA |
Armand Jasharaj |
Bug Bounty | 2022-11-05 | 2023-06-13 |
808 | Remote Command Execution in a Bank Server |
RCE
Arbitrary file read
Unrestricted file upload |
NA |
Bipin Jitiya (@win3zz) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
755 | Unrestricted file upload in Rocket TRUfusion Enterprise <= 7.9.6.0 |
Unrestricted file upload
Security code review
RCE |
Rocket Software |
Mehdi Elyassa |
Bug Bounty | 2022-11-30 | 2023-06-13 |
702 | Not usual CSP bypass case |
Unrestricted file upload
XSS
CSP bypass |
NA |
Karol Mazurek |
Bug Bounty | 2022-12-12 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
616 | PandoraFMS - Pre-Auth Remote Code Execution |
RCE
Path traversal
Arbitrary file upload
LFI
Security code review |
PandoraFMS |
esj4y (@esj4y) |
Bug Bounty | 2023-01-06 | 2023-06-13 |
609 | Uploading the Webshell using filename of Content-Disposition Header Story! |
Unrestricted file upload
Arbitrary file write |
NA |
Yashar Mohagheghi |
Bug Bounty | 2023-01-09 | 2023-06-13 |
607 | Lexmark MC3224adwe RCE exploit |
RCE
SSRF
Printer hacking
Unrestricted file upload
Local Privilege Escalation |
Lexmark |
blasty (@bl4sty) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
585 | CVE-2022-21587 (Oracle E-Business Suite Unauthenticated RCE) |
RCE
Unrestricted file upload
Zip Slip attack |
Oracle |
@vudq16 |
Bug Bounty | 2023-01-16 | 2023-06-13 |
511 | CentreStack Disclosure |
Authentication bypass
Password reset
Unrestricted file upload
RCE |
Gladinet (CentreStack) |
Michael Rand |
Bug Bounty | 2023-02-02 | 2023-06-13 |
469 | Disabling js for the win |
Unrestricted file upload
RCE |
NA |
Vuk Ivanovic |
Bug Bounty | 2023-02-10 | 2023-06-13 |
461 | Zip bomb attack |
Zip bomb
DoS
Unrestricted file upload |
NA |
Ramkumar Nadar |
Bug Bounty | 2023-02-12 | 2023-06-13 |
390 | The Tale of a Command Injection by Changing the Logo |
RCE
OS command injection
Unrestricted file upload
Directory listing
HTTP response manipulation |
NA |
0xrz (@omidxrz) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
239 | Bug Bounty: como encontrei o bug Unrestricted File Upload |
Unrestricted file upload |
NA |
Paulo Mota |
Bug Bounty | 2023-04-02 | 2023-06-13 |
217 | SQL Wildcard DoS - Hang Till Death |
DoS
File upload |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2023-04-08 | 2023-06-13 |
204 | How ChatGPT helped me find a bug |
XSS
File upload |
NA |
Abhishekgk |
Bug Bounty | 2023-04-11 | 2023-06-13 |
160 | Vocera Report Server Pwnage |
RCE
Arbitrary file upload
Path traversal
Zip Slip attack |
Stryker |
b0yd (@rwincey) |
Bug Bounty | 2023-04-24 | 2023-06-13 |
143 | Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera |
RCE
Unrestricted file upload
Path traversal
Security code review |
Oracle (Opera) |
Shubham Shah (@infosec_au) |
Bug Bounty | 2023-04-30 | 2023-06-13 |
138 | Apache Solr 8.3.1 RCE from exposed administration interface |
RCE
Unrestricted file upload
XSLT injection
Path traversal |
Apache Solr |
Nicolas Brunner |
Bug Bounty | 2023-05-01 | 2023-06-13 |
123 | When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities |
SSRF
Unrestricted file upload
Path traversal
Cloud |
Microsoft (Azure) |
Liv Matan (@terminatorLM) |
Bug Bounty | 2023-05-04 | 2023-06-13 |
114 | How a simple Directory Listing leads to PII Data Leakage, Remote Code Execution and many more vulnerabilities on a HR management subdomain |
RCE
Unrestricted file upload
Stored XSS
Information disclosure
Directory listing |
NA |
Aayush Vishnoi (@AayushVishnoi10) |
Bug Bounty | 2023-05-07 | 2023-06-13 |
110 | A deep-dive on Pluck CMS vulnerability CVE-2023-25828 |
Unrestricted file upload
RCE
Security code review |
Pluck CMS |
Matthew Hogg |
Bug Bounty | 2023-05-08 | 2023-06-13 |
40 | Kramer VIA GO² – Multiple issues |
RCE
SQL injection
Arbitrary file upload
Arbitrary file read |
Kramer |
Jim Rush (@JimSRush) |
Bug Bounty | 2023-05-31 | 2023-06-13 |