3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3073 | Error-Based SQL Injection on a WordPress website and extract more than 150k user details |
SQL injection |
NA |
Ynoof Alassiri |
Bug Bounty | 2020-10-27 | 2023-06-13 |
3048 | Silver Peak Unity Orchestrator RCE |
RCE
Authentication bypass
Path traversal
SQL injection |
Silver Peak |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-08 | 2023-06-13 |
3036 | Interesting case of SQLi |
SQL injection |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3026 | Optimizing Hunting Results in VDP for use in Bug Bounty Programs - From Sensitive Information Disclosure to Accessing Hidden APIs which can be used to Retrieve Customer Data |
Information disclosure
Broken access control
IDOR
SQL injection |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3012 | Turning Blind Error Based SQL Injection into Exploitable Boolean One |
SQL injection |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3004 | SD-PWN Part 4 — VMware VeloCloud — The Last Takeover |
RCE
Authentication bypass
Default credentials
SQL injection
Path traversal
LFI |
VMware |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
3002 | How i got easy $$$ for SQL Injection Bug |
SQL injection |
NA |
Rafi Andhika Galuh |
Bug Bounty | 2020-11-26 | 2023-06-13 |
3001 | The Story of my first critical bug |
SQL injection |
NA |
Shellbr3ak (@0xShellbr3ak) |
Bug Bounty | 2020-11-29 | 2023-06-13 |
2996 | Exploiting Blind Postgresql Injection And Exfiltrating Data In Psycopg2 |
SQL injection |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2020-11-30 | 2023-06-13 |
2960 | My Bug Bounty Journey and My First Critical Bug — Time Based Blind SQL Injection |
SQL injection |
NA |
Marx Chryz |
Bug Bounty | 2020-12-17 | 2023-06-13 |
2872 | Sql Injection via hidden parameter |
SQL injection |
NA |
Rutvik Hajare (@HajareRutvik) |
Bug Bounty | 2021-01-24 | 2023-06-13 |
2778 | Is Math.random() Safe? from missing rate limit to bypass 2fa and possible sqli |
Race condition
Lack of rate limiting
OTP bypass
SQL injection |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-02-20 | 2023-06-13 |
2754 | Admin Panel Accessed Via SQL Injection… (Ezy Boooom…😅) |
SQL injection |
NA |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2720 | How I Found Sql Injection on 8x8 , Cengage,Comodo,Automattic,20 company |
SQL injection |
Automattic
IBM
8x8 |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2021-03-12 | 2023-06-13 |
2639 | Fun sql injection — mod_security bypass |
SQL injection |
NA |
_Y000_ (@_Y000_) |
Bug Bounty | 2021-04-16 | 2023-06-13 |
2577 | How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350 |
SQL injection |
Automattic |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2021-05-05 | 2023-06-13 |
2553 | MSSQL Injection In JSON Request |
SQL injection |
NA |
Kailash (@Corrupted_brain) |
Bug Bounty | 2021-05-16 | 2023-06-13 |
2543 | Time-Based SQL Injection to Dumping the Database |
SQL injection
Android |
NA |
Naveen J (@thevillagehackr) |
Bug Bounty | 2021-05-19 | 2023-06-13 |
2522 | Hey WAF! Better Luck Next Time! 👽 |
SQL injection |
NA |
Akash Rox Starz |
Bug Bounty | 2021-05-28 | 2023-06-13 |
2410 | How I found Blind SQL Injection just by browsing and getting a unique URL |
SQL injection |
NA |
Jawad Mahdi (@hunter0x1) |
Bug Bounty | 2021-07-14 | 2023-06-13 |
2389 | How I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology & Tools |
SSTI
SQL injection
Authentication bypass
Privilege escalation
Reflected XSS |
Meta / Facebook |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2021-07-23 | 2023-06-13 |
2285 | SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection |
WAF bypass
SSRF
SQL injection |
NA |
Caesar Evan Santoso |
Bug Bounty | 2021-08-28 | 2023-06-13 |
2274 | CVE-2021-39165: A Bug Bounty Journey from a Laravel SQL Injection Vulnerability |
SQL injection |
NA |
Xuan Tuyen |
Bug Bounty | 2021-08-30 | 2023-06-13 |
2268 | SQL injection in harvard subdomain |
SQL injection |
Harvard University |
Brandon Roldan (@tomorrowisnew_) |
Bug Bounty | 2021-09-01 | 2023-06-13 |