1846 | Auth Bypass in Google Assistant |
Information disclosure
Authentication bypass |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-02-06 | 2023-06-13 |
1789 | Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing |
Android
Bruteforce
Authentication bypass |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-22 | 2023-06-13 |
1781 | Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager |
Authentication bypass
RCE
SSRF
Path traversal |
VMware |
Egor Dimitrenko (@elk0kc) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1774 | Password Reset to Admin Access |
Account takeover
Authentication bypass
Password reset |
NA |
Jesse Clark (@Hogarth45_) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1763 | WhatsApp Bug Bounty: Bypassing biometric authentication using voip |
Authentication bypass |
Meta / Facebook |
Arvind (@ar_arv1nd) |
Bug Bounty | 2022-03-05 | 2023-06-13 |
1754 | SSD Advisory – NETGEAR DGND3700v2 PreAuth Root Access |
Authentication bypass
OS command injection
RCE |
Netgear |
- |
Bug Bounty | 2022-03-09 | 2023-06-13 |
1712 | Bug Bounty catches part -1 |
Authentication bypass
Information disclosure
Broken Access Control |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2022-03-20 | 2023-06-13 |
1704 | Authentication bypass using root array |
Authentication bypass
Information disclosure |
NA |
Eslam Akl (@eslam3kll) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1698 | Finding bugs to trigger Unauthenticated Command Injection in a NETGEAR router (PSV-2022–0044) |
XSS
Arbitrary file read
Authentication bypass
OS command injection
RCE |
Netgear |
stypr (@stereotype32) |
Bug Bounty | 2022-03-25 | 2023-06-13 |
1591 | Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL |
Cross-tenant vulnerability
Privilege escalation
Authentication bypass
Cloud |
Microsoft |
Shir Tamari (@shirtamari) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1574 | CVE-2022-0540 - Authentication bypass in Seraph |
Authentication bypass |
NA |
Khoa Dinh (@_l0gg) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1511 | External Authentication bypass in ingress-nginx |
Path traversal
Authentication bypass |
Kubernetes |
Niemiec Marcin (@xvnpw) |
Bug Bounty | 2022-05-29 | 2023-06-13 |
1485 | CVE-2022-1040 Sophos XG Firewall Authentication bypass |
Authentication bypass
RCE |
Sophos |
Nguyễn Đình Biển (@biennd279) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1483 | My first CVE-2022–31289 |
Authentication bypass
403 bypass
HTTP response manipulation |
Sonatype |
Praveen Mali (@pmmali_) |
Bug Bounty | 2022-06-11 | 2023-06-13 |
1437 | Lock Screen Bypass Exploit of Android Devices (CVE-2022–20006) |
Authentication bypass
Lock screen bypass |
Google |
Joshua Nearchos |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1416 | Pwning ManageEngine — From PoC to Exploit: A deep dive into CVE-2020–11531 and CVE-2020–11532 |
Path traversal
RCE
Authentication bypass |
Zoho |
Erik Wynter (@WynterErik) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1405 | Admin account takeover via weird Password Reset Functionality |
Account takeover
Authentication bypass
Password reset |
NA |
Mahmoud Youssef (@0xmahmoudjo0) |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1390 | Account Takeover via Response Manipulation |
Authentication bypass
Account takeover
MFA bypass
HTTP response manipulation |
NA |
BUG HUNTER |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1338 | Riding The Inforail To Exploit Ivanti Avalanche |
RCE
Insecure deserialization
Race condition
Authentication bypass |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1331 | Pwn2Own Miami 2022: Inductive Automation Remote Code Execution |
RCE
Authentication bypass |
Inductive Automation Ignition |
Sector 7 (@sector7_nl) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1319 | With Management Comes Risk: Finding Flaws in FileWave MDM |
Authentication bypass
Hardcoded credentials
Information disclosure |
Filewave |
Claroty%27s Team82 (@Claroty) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1311 | Advisory | Roxy-WI Unauthenticated Remote Code Executions CVE-2022-31137 |
RCE
Authentication bypass |
Roxy-WI |
Nuri Çilengir (@ncilengir) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1265 | Dancing on the architecture of VMware Workspace ONE Access (ENG) |
Authentication bypass
SQL injection
RCE |
VMware |
Petrus Viet (@VietPetrus) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1264 | From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager |
Authentication bypass
Information disclosure
Local Privilege Escalation |
VMware |
Steven Seeley (@steventseeley) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1245 | IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit |
Authentication bypass
Information disclosure
CSRF
RCE
Local Privilege Escalation |
VMware |
Steven Seeley (@steventseeley) |
Bug Bounty | 2022-08-11 | 2023-06-13 |