3720 | Adding a malicious notebook to be treated like a trusted notebook in Google Colab — 1337$ |
Authorization flaw
Logic flaw |
Google |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2020-01-17 | 2023-06-13 |
3719 | How I accidentally found Bug in Google Search Console |
Logic flaw
Authorization flaw |
Google |
Tomi (@noobe_io) |
Bug Bounty | 2020-01-18 | 2023-06-13 |
3718 | GGvulnz — How I hacked hundreds of companies through Google Groups |
Logic flaw |
Google |
Milan Magyar |
Bug Bounty | 2020-01-20 | 2023-06-13 |
3714 | User Account Takeover via Signup Feature | Bug Bounty POC |
Account takeover
Logic flaw
Authorization flaw |
NA |
Muzammil Kayani (@muzammilabbas2) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3713 | Facebook Vulnerability: Hidden “Community Manager” in Pages due to “Invitation Accept” logic |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3695 | 2FA Bypass via Logical Rate Limiting Bypass |
MFA bypass
Logic flaw |
NA |
Jeppe Bonde Weikop |
Bug Bounty | 2020-01-30 | 2023-06-13 |
3661 | Plan Change Logic in Google Fiber (Webpass) |
Logic flaw
Payment tampering |
Google |
Craig Arendt (@signalchaos) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3628 | Abusing Slack for Offensive Operations |
Logic flaw |
Slack |
Cody Thomas (@its_a_feature_) |
Bug Bounty | 2020-03-04 | 2023-06-13 |
3622 | Breaking the Competition (Bug Bounty Write-up) |
Race condition
DoS
Logic flaw
Session management issue |
NA |
George O (@georgeomnet) |
Bug Bounty | 2020-03-08 | 2023-06-13 |
3621 | The unexpected Google wide domain check bypass |
Logic flaw |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2020-03-08 | 2023-06-13 |
3619 | Vulnerable design leads to personal data leakage- yet another case of an inter-application vulnerability… |
Logic flaw |
NA |
Marcin Szydlowski (@SecurityKsl) |
Bug Bounty | 2020-03-09 | 2023-06-13 |
3605 | Blocked User Can Send Notification Due to Logical Bug in Instagram | First Instagram Bug |
Logic flaw |
Meta / Facebook |
Divyanshu Shukla (@justm0rph3u5) |
Bug Bounty | 2020-03-14 | 2023-06-13 |
3601 | Weak session validation bug let you login even after changing the session IDs and logging out from the accounts |
Logic flaw
Session management issue |
viator.com |
Manasjha (@manas_hunter) |
Bug Bounty | 2020-03-16 | 2023-06-13 |
3583 | Account Takeover Flow In Mail.ru s Ext.A Domain [ $150 ] |
Logic flaw
Account takeover |
NA |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-03-26 | 2023-06-13 |
3580 | I Want that Cookie !!! |
Logic flaw |
NA |
Adnan Malik (@infoadnanmalik) |
Bug Bounty | 2020-03-27 | 2023-06-13 |
3569 | The story of my first ever, 1500$, bounty from Facebook. |
Logic flaw |
Meta / Facebook |
Ashok Chapagai (@ashokcpg) |
Bug Bounty | 2020-04-01 | 2023-06-13 |
3561 | Cannot Delete Post on Facebook Group: Facebook Bug Bounty |
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-04-04 | 2023-06-13 |
3560 | Page Admin Disclosure: Facebook Bug Bounty 2020 |
Information disclosure
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-04-04 | 2023-06-13 |
3549 | Business Logic Errors - A New Look |
Logic flaw |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-04-14 | 2023-06-13 |
3542 | Here is the Non Technical write-up on Technical Bug for My Second Bounty of $xxxx From Facebook |
Logic flaw
Privacy issue |
Meta / Facebook |
Ashok Chapagai (@ashokcpg) |
Bug Bounty | 2020-04-17 | 2023-06-13 |
3538 | Google Maps API (Not the Key) Bugs That I Found Over the Years |
Logic flaw |
Google |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-04-19 | 2023-06-13 |
3531 | Hiding ourself in close friend’s list and avoiding victim to remove us from his close friend’s list. |
Authorization flaw
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-04-23 | 2023-06-13 |
3516 | Account taken over in style !!! |
Logic flaw
CSRF
Account takeover |
NA |
kishore hariram (@kishorehariram) |
Bug Bounty | 2020-04-30 | 2023-06-13 |
3505 | #BugBounty — Adding Money Using Response Modification |
Payment tampering
Logic flaw |
NA |
Line_no 6 |
Bug Bounty | 2020-05-03 | 2023-06-13 |
3478 | Logical Bug which let me stop Users from Creating Ads at a Website |
Logic flaw
DoS |
NA |
Merbin Russel (e_23_e) |
Bug Bounty | 2020-05-17 | 2023-06-13 |