1329 | Permanent Crash Instagram Followers. |
DoS |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1326 | Un3xpected DoS Attack on Profile Pictur3 |
DoS |
NA |
Roxst4r (@mveswar98) |
Bug Bounty | 2022-07-23 | 2023-06-13 |
1321 | Technical Advisory – Multiple vulnerabilities in Nuki smart locks (CVE-2022-32509, CVE-2022-32504, CVE-2022-32502, CVE-2022-32507, CVE-2022-32503, CVE-2022-32510, CVE-2022-32506, CVE-2022-32508, CVE-2022-32505) |
Memory corruption
DoS
Broken Access Control
Sensitive Information Sent Over an Unencrypted Channel |
Nuki |
Daniel Romero (@daniel_rome) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1317 | DoS worth $650 ? Interesting right! |
DoS
Pixel flood attack |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1308 | CVE-2022-31813: Forwarding Addresses Is Hard |
Host header injection
DoS
IP address spoofing |
Internet Bug Bounty (Apache HTTPD) |
Gaetan Ferry (@_mabote_) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1244 | FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies |
HTTP Request Smuggling
DoS |
NA |
Bahruz Jabiyev (@BahruzJabiyev) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1226 | Hacking Zyxel IP cameras to gain a root shell |
Missing authentication
DoS
Information disclosure
Local Privilege Escalation |
Zyxel |
Eric Urban |
Bug Bounty | 2022-08-14 | 2023-06-13 |
1215 | Multiple Denial of Service (DoS) Vulnerabilities in GoProxy, Smokescreen libraries |
DoS |
Stripe |
Lorenzo Stella (@lorenzostella) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1206 | Let%27s Dance in the Cache - Destabilizing Hash Table on Microsoft IIS! |
DoS
Web cache poisoning
Authentication bypass |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1203 | Outlook CVE-2022-35742 |
DoS |
Microsoft |
insu (@hpy_insu) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1183 | Oracle SBC: Multiple Security Vulnerabilities Leading to Unauthorized Access and Denial of Service |
IDOR
Path traversal
DoS |
Oracle |
Harold Zang |
Bug Bounty | 2022-08-23 | 2023-06-13 |
1181 | 2-byte DoS in freebsd-telnetd / netbsd-telnetd / netkit-telnetd / inetutils-telnetd / telnetd in Kerberos Version 5 Applications - Binary Golf Grand Prix 3 |
DoS |
FreeBSD Security Team |
Pierre Kim (@PierreKimSec) |
Bug Bounty | 2022-08-24 | 2023-06-13 |
1179 | Crashing Industrial Control Systems at Pwn2Own Miami 2022 |
DoS
Memory corruption
RCE |
Unified Automation |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1137 | Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique) |
Web cache poisoning
XSS
DoS |
Glassdoor |
Harel (@h4r3l) |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1136 | Discovery of CVE-2022-35406 |
Logic flaw
Referer leakage |
PortSwigger |
Mr. Vrushabh (@doshi_vrushabh) |
Bug Bounty | 2022-09-03 | 2023-06-13 |
1134 | Your Amiibo’s Haunted |
Memory corruption
Buffer Overflow
DoS |
Flipper Zero |
VVX7 (@VV_X_7) |
Bug Bounty | 2022-09-05 | 2023-06-13 |
1130 | A Bug That Was 23 Years Old Or Not |
DoS |
Internet Bug Bounty (curl) |
Daniel Stenberg (@bagder) |
Bug Bounty | 2022-09-05 | 2023-06-13 |
1101 | Avalanche remote network crash |
DoS |
Ava Labs |
Pter Szilgyi (@peter_szilagyi) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1082 | Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS |
DoS |
Unified Automation |
Sector 7 (@sector7_nl) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1059 | Apollo Router Security Audit Report (Q2 2022) |
DoS
CSRF |
Apollo GraphQL |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1054 | TypeORM Prototype Pollution Leading To SQL Injection (CVE-2022-36531) |
DoS
SQL injection |
TypeORM |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1027 | Layer 2 network security bypass using VLAN 0, LLC/SNAP headers and invalid length |
Layer 2 networking vulnerability
Ethernet
MiTM
DoS |
Microsoft
Cisco |
Etienne Champetier / champtar |
Bug Bounty | 2022-09-27 | 2023-06-13 |
1010 | Zoneminder – Web App Testing – Oct 2022 |
DoS
Log injection
CSRF
Stored XSS |
ZoneMinder |
Trenches of IT (@TrenchesofIT) |
Bug Bounty | 2022-09-30 | 2023-06-13 |
961 | Some Vulnerabilities Don’t Have A Name |
ReDoS
Memory leak |
Node.js third-party modules (debug) |
Mario Teixeira |
Bug Bounty | 2022-10-13 | 2023-06-13 |
912 | Stranger Strings: An exploitable flaw in SQLite |
Memory corruption
Buffer Overflow
DoS |
SQLite |
Andreas Kellas |
Bug Bounty | 2022-10-25 | 2023-06-13 |