1666 | Cloud SSRF Exploitation |
SSRF |
NA |
Dan Barros |
Bug Bounty | 2022-04-04 | 2023-06-13 |
1660 | CloudKit Share Records leak the title of private iCloud files |
IDOR
Broken Access Control |
Apple |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1653 | Azure Active Directory Exposes Internal Information |
Cloud
Information disclosure
Azure AD |
Microsoft (Azure) |
Counter Threat Unit Research Team |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1630 | Threat Evasion for aws:multifactorAuthPresent condition using Cloudshell |
MFA bypass |
AWS |
Falcnix (@falcnix) |
Bug Bounty | 2022-04-13 | 2023-06-13 |
1605 | Smashing the Modern Web Tech Stack — Part 1: The Evolving Threat Landscape in 2022 and DOM-based XSS in Cloud-Native React Apps. |
Open redirect
XSS |
NA |
MalwareJoe |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1604 | Security issues with cloudflare/odoh-server-go and the ODoH RFC draft |
SSRF |
Cloudflare |
Frans Rosén (@fransrosen) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1595 | Azure Monitor – Malicious KQL Query |
Privilege escalation
Cloud |
Microsoft |
Joosua Santasalo (@SantasaloJoosua) |
Bug Bounty | 2022-04-27 | 2023-06-13 |
1591 | Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL |
Cross-tenant vulnerability
Privilege escalation
Authentication bypass
Cloud |
Microsoft |
Shir Tamari (@shirtamari) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1571 | Cloudflare Pages, part 1: The fellowship of the secret |
Command injection
Container escape
Bash Path injection
RCE
Local Privilege Escalation
Information disclosure |
Cloudflare |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1546 | Variant Cloud Analysis |
Default credentials |
NA |
jspin (@jespinhara) |
Bug Bounty | 2022-05-18 | 2023-06-13 |
1474 | Microsoft Azure Synapse Pwnalytics |
Privilege escalation
Cloud |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-06-13 | 2023-06-13 |
1470 | SynLapse – Technical Details for Critical Azure Synapse Vulnerability |
Cross-tenant vulnerability
RCE
Cloud |
Microsoft |
Tzah Pahima (@TzahPahima) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1464 | Hertzbleed Attack |
Side-channel attack
Hardware hacking
Cryptographic issues |
Intel
Cloudflare
Microsoft |
Yingchen Wang (@YingchenWang96) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1429 | Hyperlink Injection On IRC Cloud |
Hyperlink injection |
IRCCloud |
Aswin K V (@deep_marketer_) |
Bug Bounty | 2022-06-26 | 2023-06-13 |
1360 | Ability to login as google staff in Google Cloud Community |
Privilege escalation |
Google |
Gaurav Bhatia |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1343 | Logging Passwords in Plaintext in Azure Arc |
Information disclosure
Local Privilege Escalation
Cloud |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1281 | Hijacking email with Cloudflare Email Routing |
HTTP response manipulation
Privilege escalation |
NA |
Albert Pedersen (@AlbertSPedersen) |
Bug Bounty | 2022-08-03 | 2023-06-13 |
1276 | Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI |
Local Privilege Escalation
Cloud |
Microsoft |
Nir Ohfeld (@nirohfeld) |
Bug Bounty | 2022-08-05 | 2023-06-13 |
1266 | Bypassed Cloudflare’s Web Application Firewall (WAF) |
XSS
HTML injection
WAF bypass |
NA |
Ansh Vaid (@anshvaid4) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1257 | Google Cloud Shell - Command Injection |
OS command injection
RCE
Cloud |
Google |
Bugra Eskici (@bugraeskici) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1256 | How I earned a $6000 bug bounty from Cloudflare |
Path traversal |
Cloudflare |
ANDRI |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1246 | The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors |
Privilege escalation
Cross-tenant vulnerability
OS command injection
Local Privilege Escalation
Cloud |
Google
Microsoft
Aiven |
Shir Tamari (@shirtamari) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1207 | You Have One New Appwntment: Exploiting iCalendar Properties in Enterprise Applications |
XSS
SMTP injection |
VMware
Synology
Apple
Microsoft
Google
NextCloud |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1143 | Azure Synapse: Local Privilege Escalation Vulnerability in Spark |
Race condition
Local Privilege Escalation
Cloud |
Microsoft |
Tzah Pahima (@TzahPahima) |
Bug Bounty | 2022-09-01 | 2023-06-13 |
1060 | AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes |
Cloud
Cross-tenant vulnerability
Authorization flaw |
Oracle |
Elad Gabay (@eladgabay_) |
Bug Bounty | 2022-09-20 | 2023-06-13 |