1013 | Security vs Compliance-Cloudflare Password Policy Restriction Bypass |
Client-side enforcement of server-side security |
Cloudflare |
Lohith Gowda M (@lohigowda_in) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
999 | Appsmith Patches Full-Read SSRF Vulnerabilities Reported by CloudSEK |
SSRF |
Appsmith |
Sparsh Kulshrestha (@d0tdotslash) |
Bug Bounty | 2022-10-05 | 2023-06-13 |
942 | The Danger of Falling to System Role in AWS SDK Client |
Cloud
Privilege escalation
Security misconfiguration |
NA |
Fracensco Lacerenza (@lacerenza_fra) |
Bug Bounty | 2022-10-18 | 2023-06-13 |
815 | MEGA’s Unlimited Cloud Storage Vulnerability |
Logic flaw
Privilege escalation |
MEGA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2022-11-17 | 2023-06-13 |
809 | SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover |
Account takeover
Azure AD
Cloud |
Microsoft |
Tomer Nahum (@TomerNahum1) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
797 | A Confused Deputy Vulnerability in AWS AppSync |
Confused deputy
Cloud
Privilege escalation |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
749 | Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access |
Cloud
SQL injection
Privilege escalation
Information disclosure |
IBM |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
717 | {JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF |
WAF bypass
SQL injection |
Palo Alto Networks
AWS
Cloudflare
F5
Imperva |
Noam Moshe |
Bug Bounty | 2022-12-08 | 2023-06-13 |
699 | AWS ECR Public Vulnerability |
Cloud
Privilege escalation
Broken Access Control |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2022-12-13 | 2023-06-13 |
663 | Passwordless Persistence and Privilege Escalation in Azure |
Privilege escalation
Cloud
Azure AD |
Microsoft |
Andy Robbins (@_wald0) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
659 | ACSESSED: Cross-tenant network bypass in Azure Cognitive Search |
Cloud
Cross-tenant vulnerability
Privilege escalation |
Microsoft (Azure) |
Emilien Socchi (@emiliensocchi) |
Bug Bounty | 2022-12-22 | 2023-06-13 |
655 | CRLF Injection — xxx$ — How was it possible for me to earn a bounty with the Cloudflare WAF? |
CRLF injection |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2022-12-24 | 2023-06-13 |
614 | Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability |
CORS misconfiguration |
Google |
Borna Nematzadeh (@LogicalHunter) |
Bug Bounty | 2023-01-06 | 2023-06-13 |
598 | Client-Side SSRF to Google Cloud Project Takeover [Google VRP] |
SSRF
CSRF
Open redirect |
Google |
Dohyun Lee |
Bug Bounty | 2023-01-12 | 2023-06-13 |
596 | SSH key injection in Google Cloud Compute Engine [Google VRP] |
OS command injection
RCE |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-12 | 2023-06-13 |
594 | Bypassing authorization in Google Cloud Workstations [Google VRP] |
Account takeover
OAuth
URL validation bypass |
Google |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
590 | XSS using postMessage in Google Cloud Theia notebooks [Google VRP] |
XSS
postMessage |
Google |
Sreeram KL (@kl_sree) |
Bug Bounty | 2023-01-15 | 2023-06-13 |
582 | AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass |
Cloud
Logic flaw
CloudTrail bypass |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
580 | How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services |
SSRF
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-01-17 | 2023-06-13 |
569 | EmojiDeploy: Smile! Your Azure web service just got RCE’d ._. |
RCE
Cloud
CSRF
CORS misconfiguration |
Microsoft (Azure) |
Liv Matan (@terminatorLM) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
558 | Bypassing Cloudflare WAF: XSS via SQL Injection |
Reflected XSS
SQL injection
WAF bypass |
NA |
Uku Sõrmus |
Bug Bounty | 2023-01-21 | 2023-06-13 |
555 | How i was able to get critical bug on google by get full access on [Google Cloud BI Hackathon] |
Information disclosure |
Google |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
501 | Azure security — Internal recon leveraging lack of access control |
Azure AD
Cloud
Security misconfiguration
Privilege escalation |
Microsoft (Azure) |
Molx32 |
Bug Bounty | 2023-02-02 | 2023-06-13 |
476 | Azure Ad Kerberos Tickets: Pivoting To The Cloud |
Active Directory
Cloud
Lateral movement |
NA |
Edwin David |
Bug Bounty | 2023-02-09 | 2023-06-13 |
449 | Assumed Breach Assessment Case Study: Uncovering WeSecureApp’s Approach |
Internal pentest
Missing authentication
Hardcoded credentials
Cloud |
NA |
WeSecureApp (@wesecureapp) |
Bug Bounty | 2023-02-14 | 2023-06-13 |