3869 | CPDoS: Cache Poisoned Denial of Service |
DoS
Web cache poisoning |
Microsoft
Amazon
Akamai
Cloudflare
Yahoo! / Verizon Media
Play Framework |
Hoai Viet Nguyen (@hvnguyen86) |
Bug Bounty | 2019-10-22 | 2023-06-13 |
3868 | NFC Beaming Bypasses Security Controls in Android [CVE-2019-2114] |
NFC
Android |
Google |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3867 | How I earned $$$$ by finding confidential customer data including plain-text passwords! |
Directory listing
Information disclosure |
NA |
Sushant Soni (@sushantsoni5392) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3866 | Responsible denial of service with web cache poisoning |
DoS
Web cache poisoning |
Tesla
HackerOne
Deliveroo
Bitbucket
Paypal
Meta / Facebook
Twitter |
James Kettle (@albinowax) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3865 | Session Expiration Bypass in Facebook Creator App |
Session expiration issue |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3864 | How to Takover a ldap server. |
Misconfigured LDAP server |
NA |
Ashish Kunwar (@D0rkerDevil) |
Bug Bounty | 2019-10-25 | 2023-06-13 |
3863 | Illegal Rendered at Download Feature in Several Apps (including Opera Mini) that Lead to Extension Manipulation (with RTLO) |
RTLO |
Opera |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-10-26 | 2023-06-13 |
3862 | Android Reddit App leaks images |
Information disclosure |
Reddit |
Eric Urban |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3861 | How I hacked 50+ Companies in 6 hrs |
SSTI
RCE |
NA |
Vignesh C (@pwn_r00t) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3860 | [Leak] Can I take the user information, please?!! |
Information disclosure |
NA |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3859 | XSS to Account Takeover |
XSS
CSRF |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3858 | Cross Site Request Forgery Critical Exploitable IN Infected Site? |
CSRF |
NA |
Hossam Mesbah |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3857 | 5,000 USD XSS Issue at Avast Desktop AntiVirus for Windows (Yes, Desktop!) |
Reflected XSS |
Avast |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3856 | GraphQL introspection leads to sensitive data disclosure. |
Information disclosure |
NA |
Eshan Singh (@R0X4R) |
Bug Bounty | 2019-10-30 | 2023-06-13 |
3855 | Live Video facebook application (Android) its not expired when log out the device on https://www.facebook.com/settings?tab=security§ion=sessions&view |
Logic flaw |
Meta / Facebook |
Naufal Septiadi |
Bug Bounty | 2019-10-30 | 2023-06-13 |
3854 | Download this tool and you win |
Open redirect |
NA |
zoid (@z0idsec) |
Bug Bounty | 2019-10-31 | 2023-06-13 |
3853 | Filling in the Blanks: Exploiting Null Byte Buffer Overflow for a $40,000 Bounty |
Null byte buffer overflow
Memory corruption |
NA |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-11-01 | 2023-06-13 |
3852 | XSS will never die |
XSS |
NA |
Oleksandr Opanasiuk (@Lekssik2) |
Bug Bounty | 2019-11-02 | 2023-06-13 |
3851 | BugBounty | A Simple SSRF |
SSRF
DNS rebinding |
NA |
Jinone (@jinonehk) |
Bug Bounty | 2019-11-05 | 2023-06-13 |
3850 | Bypassing GitHub%27s OAuth flow |
OAuth
Authorization bypass |
GitHub |
Teddy Katz (@not_aardvark) |
Bug Bounty | 2019-11-05 | 2023-06-13 |
3849 | BugBounty | A Simple SSRF |
SSRF
DNS rebinding |
NA |
Jinone (@jinonehk) |
Bug Bounty | 2019-11-05 | 2023-06-13 |
3848 | How I Hacked Dutch Government in 5 Minutes? Twitter Account Takeover |
Broken link hijacking |
Dutch Government |
Numan ÖZDEMİR (@numanozdemircom) |
Bug Bounty | 2019-11-06 | 2023-06-13 |
3847 | A simple post auth bypass leads to unauthorized web server access |
Default credentials |
NA |
Hein Thant Zin (@H3Lowr) |
Bug Bounty | 2019-11-08 | 2023-06-13 |
3846 | BugBounty: How I Cracked 2FA (Two-Factor Authentication) with Simple Factor Brute-force !!! 😎 |
MFA bypass
Lack of rate limiting |
NA |
Akash Agrawal (@akashmagrawal) |
Bug Bounty | 2019-11-08 | 2023-06-13 |
3845 | DOM-Based XSS | Bug Bounty Writeup |
DOM XSS |
NA |
HacknPentest (@HacknPentest) |
Bug Bounty | 2019-11-10 | 2023-06-13 |