357 | GitHub Security Lab audited DataHub: Here’s what they found |
SSRF
Insecure deserialization
Cypher injection
Authentication bypass
Authorization bypass
XSS
Open redirect
JWT
JSON injection
Cryptographic issues
Session expiration issue
Security code review |
DataHub |
Alvaro Muñoz (@pwntester) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
345 | Authentication Bypass Vulnerability in Mura CMS and Masa CMS (CVE-2022-47003 and CVE-2022-47002) |
Authentication bypass
Security code review
ColdFusion |
Mura CMS
Masa CMS |
Brian (@hoyahaxa) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
339 | Attacking .NET Web Services |
Security code review
Arbitrary file read
Arbitrary file write
SSRF |
Siemens |
b0yd (@rwincey) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
337 | WordPress BuddyForms Plugin — Unauthenticated Insecure Deserialization (CVE-2023–26326) |
Insecure deserialization
Security code review
RCE |
NA |
Joshua Martinelle (@J0_mart) |
Bug Bounty | 2023-03-07 | 2023-06-13 |
332 | PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 |
RCE
OS command injection
Security code review |
Netgear |
Zion Basque (@mahal0z) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
330 | CorePlague: Severe Vulnerabilities in Jenkins Server Lead to RCE |
RCE
XSS
Security code review |
Jenkins |
Ilay Goldman (@GoldmanIlay) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
327 | EJS - Server Side Prototype Pollution gadgets to RCE |
Server-side prototype pollution
RCE
Security code review |
Node.js third-party modules (EJS) |
Mizu (@kevin_mizu) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
312 | Dolibarr : unauthenticated contacts database theft |
SQL injection
Security code review |
Dolibarr |
Vladimir |
Bug Bounty | 2023-03-13 | 2023-06-13 |
298 | IP spoofing and SQL injection in Textcube |
SQL injection
IP spoofing
HTTP header attack
Security code review |
Textcube |
Sjoerd Langkemper |
Bug Bounty | 2023-03-15 | 2023-06-13 |
286 | Remote code execution in BIRT Viewer ≤ 4.12.0 (CVE-2023-0100) |
RCE
RFI
URL validation bypass
Security code review |
Eclipse Foundation |
Louis Wolfers (@TG91aXMK) |
Bug Bounty | 2023-03-17 | 2023-06-13 |
279 | Parallels Desktop Toolgate Vulnerability |
Path traversal
Arbitrary file write
Security code review
Thick client |
Parallels |
Alexandre Adamski (@NeatMonster_) |
Bug Bounty | 2023-03-20 | 2023-06-13 |
259 | High severity vulnerability fixed in WordPress Elementor Pro plugin. |
Broken Access Control
Privilege Escalation
Security code review |
Elementor |
Jerome Bruandet |
Bug Bounty | 2023-03-28 | 2023-06-13 |
254 | It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS |
RCE
Stored XSS
Security code review |
LibreNMS |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
252 | CVE-2022-37734: graphql-java Denial-of-Service |
GraphQL
DoS
Security code review |
graphql-java |
Artem Logutov |
Bug Bounty | 2023-03-30 | 2023-06-13 |
241 | Beware of Java%27s String.getBytes |
Hash collision
Cryptographic issues
Security code review |
Swiss E-Voting |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2023-03-31 | 2023-06-13 |
240 | Finding RCE in NodeJS templating engine %27Eta%27 - CVE-2022-25967 |
RCE
Server-side prototype pollution
Security code review |
Eta |
Rayhan Ahmed Niloy (@Rayhan0x01) |
Bug Bounty | 2023-04-01 | 2023-06-13 |
208 | Pretalx Vulnerabilities: How to get accepted at every conference |
Arbitrary file read
Arbitrary file write
RCE
Security code review |
Pretalx |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
205 | Losing control over Schneider%27s EcoStruxure Control Expert |
RCE
Path traversal
Security code review |
Schneider Electric |
Ruben Santamarta (@reversemode) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
192 | (CVE-2023-2017) Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension |
SSTI
RCE
Security code review |
Shopware |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
178 | Vulnerability Spotlight: CVE-2023-0264 |
OpenID Connect
OAuth
Authentication flaw
Privilege escalation
Security code review |
Keycloack |
Timo Müller (@mtimo44) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
159 | Odoo: Get your Content Type right, or else! |
XSS
Security code review |
Odoo |
Dennis Brinkrolf (@DBrinkrolf) |
Bug Bounty | 2023-04-24 | 2023-06-13 |
153 | Finding XSS in a million websites (cPanel CVE-2023-29489) |
Reflected XSS
Security code review |
cPanel |
Shubham Shah (@infosec_au) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
152 | Git Arbitrary Configuration Injection (CVE-2023-29007) |
Logic flaw
Arbitrary Code Execution
Security code review |
Git |
André Baptista (@0xacb) |
Bug Bounty | 2023-04-26 | 2023-06-13 |
143 | Exploiting an Order of Operations Bug to Achieve RCE in Oracle Opera |
RCE
Unrestricted file upload
Path traversal
Security code review |
Oracle (Opera) |
Shubham Shah (@infosec_au) |
Bug Bounty | 2023-04-30 | 2023-06-13 |
120 | Bullied by Bugcrowd over Kape CyberGhost disclosure |
Local Privilege Escalation
OS command injection
Security code review |
Kape (CyberGhost) |
Ceri Coburn (@_ethicalchaos_) |
Bug Bounty | 2023-05-05 | 2023-06-13 |