3479 | How I was able to make users loss of money on Google Pay |
Clickjacking |
Google |
santuySec (@santuySec) |
Bug Bounty | 2020-05-16 | 2023-06-13 |
3448 | How I was able to see Private Video Uploader Via Facebook Rights Manager.[Responsible Disclosure] |
Information disclosure |
Meta / Facebook |
Kishore TK (@kishoretk_off) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3429 | Double URL-encoded XSS |
Reflected XSS |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-06-02 | 2023-06-13 |
3387 | All *.intercom.help subdomains vulnerable to Subdomain Takeover from intercom Service |
Subdomain takeover |
Intercom |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3386 | How I was able to buy t-shirt for €1 — Payment Price Manipulation |
Payment tampering |
NA |
Muztahidul Tanim (@TheMuztahidul) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3372 | How i was able to chain bugs and gain access to internal okta instance |
Missing authentication |
NA |
Mmohammed Eldeeb (@malcolmx0x) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3360 | How I was able to take over any account via the Password Reset Functionality. |
Password reset
Account takeover |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3327 | How i was able to bypass Email Confirm — P4 |
Information disclosure |
NA |
Mohammed Ehssan (@alone_Wwolf) |
Bug Bounty | 2020-07-06 | 2023-06-13 |
3311 | How I was able to change victim’s password using IDN Homograph Attack |
IDN homograph attack |
NA |
Abhishek Karle (@AbhishekKarle3) |
Bug Bounty | 2020-07-11 | 2023-06-13 |
3302 | I am able to see user’s sensitive data through JSON file. |
Information disclosure
Authorization flaw |
NA |
Saurabh siddharam sanmane (@saurabhsanmane2) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3279 | An unreproducable bug due to the load balancer, an unusual Open Redirect bug |
Open redirect |
NA |
tololovejoi (@tolo7010) |
Bug Bounty | 2020-07-27 | 2023-06-13 |
3249 | How I was able to do Mass Account Takeover[Bug Bounty] |
Account takeover
Password reset |
NA |
Not Rickyy (@RickyyNot) |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3230 | Group Admin Can’t Able to Moderate Comments When Posted Through Page : Facebook Bug Bounty 2020 |
Logic flaw |
Meta / Facebook |
Prakash Panta (@Prakashpanta268) |
Bug Bounty | 2020-08-11 | 2023-06-13 |
3229 | How I was able to find page/personal account disclosure on Instagram |
Information disclosure |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-08-11 | 2023-06-13 |
3215 | How I was able to send Authentic Emails as others — Google VRP [Resolved] |
Logic flaw
HTML injection
Email spoofing
Open mail relay |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2020-08-15 | 2023-06-13 |
3214 | Disclosing wifi password via content provider injection in Xiaomi |
Content provider injection
Vulnerable Android content provider
Android |
Xiaomi |
Vishwaraj Bhattrai (@vishwaraj101) |
Bug Bounty | 2020-08-16 | 2023-06-13 |
3195 | How I was able to find easy P1 just by doing Recon |
LFI |
NA |
Kirtan Patel (@kirtanpatel9111) |
Bug Bounty | 2020-08-22 | 2023-06-13 |
3175 | How_i_was_able_to_pawned_website_via_escilating_webcache deception to rce |
Web cache deception
SSRF
RCE |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2020-09-05 | 2023-06-13 |
3162 | SQL Injection & Remote Code Execution - Double P1 |
SQL injection
RCE |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-09-13 | 2023-06-13 |
3142 | suPHP - The vulnerable ghost in your shell |
Local Privilege Escalation |
NA |
Maxime (@punkeel) |
Bug Bounty | 2020-09-21 | 2023-06-13 |
3141 | suPHP - The vulnerable ghost in your shell🎯Business Logic Flaw in Google Acquisition! (Hall Of Fame)🎯 |
Logic flaw |
Google |
Ritesh Gohil (@RiteshG37659480) |
Bug Bounty | 2020-09-21 | 2023-06-13 |
3139 | #Bugbounty- “How I was able to see other users Payments in a travel application” — IDOR #800$ |
IDOR
Information disclosure |
NA |
ganiganesh (@ganiganeshss79) |
Bug Bounty | 2020-09-22 | 2023-06-13 |
3068 | Wormable remote code execution in Alien Swarm |
RCE |
Valve |
mev |
Bug Bounty | 2020-10-30 | 2023-06-13 |
3034 | Smuggling an (Un)exploitable XSS |
HTTP Request Smuggling
XSS |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3032 | Theoretically Possible To Practical Account Takeover |
IDOR
Account takeover |
NA |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2020-11-14 | 2023-06-13 |