1606 | Open Redirection into Bentley System |
XSS |
Bentley Systems |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1605 | Smashing the Modern Web Tech Stack — Part 1: The Evolving Threat Landscape in 2022 and DOM-based XSS in Cloud-Native React Apps. |
Open redirect
XSS |
NA |
MalwareJoe |
Bug Bounty | 2022-04-21 | 2023-06-13 |
1519 | How an Open Redirection Leads to an Account Takeover? |
Open redirect
Account takeover |
NA |
Mahendra Purbia (@Mah3Sec_) |
Bug Bounty | 2022-05-26 | 2023-06-13 |
1506 | From open redirect to RCE in one week |
Open redirect
SSRF
Insecure deserialization
LFI
RCE |
Mail.ru |
byq (@ByQwert) |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1404 | A swag for a Open Redirect — Google Dork — Bug Bounty |
Open redirect |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1397 | How I found Open redirect on Bug crowd public program in 2 day |
Open redirect |
NA |
Ittipatjitrada (@IttipatJitrada) |
Bug Bounty | 2022-07-06 | 2023-06-13 |
1393 | How I find open redirect in Facebook |
Open redirect |
Brave Software |
Abhinav Kumar (@abhinavsecond) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1369 | From Open Redirect to Reflected XSS manually |
Open redirect
Reflected XSS |
NA |
Rodric |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1344 | How i was able to bypass Open Redirect 3 times on same program. |
Open redirect |
NA |
himanshu pdy (@himanshu_pdy) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1267 | Simple Open Redirect Bypass. |
Open redirect |
NA |
Harshad Gaikwad (@h4rsh4d) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1262 | Security Implications of URL Parsing Differentials |
Open redirect
URL parsing differentials bug
URL parsing issue |
Thomas Chauchefoin (@swapgs) |
Security Implications of URL Parsing Differentials |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1248 | My Experience on Hacking the Dutch Government |
XSS
Open redirect
CSRF
Account takeover |
Dutch Government |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1233 | Escalating Open Redirect to XSS |
Open redirect
XSS |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1217 | Open Redirect at Nvidia |
Open redirect |
Nvidia |
Mohamed Abdelhady |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1198 | Never underestimate the power of open redirect, a story of a full account takeover |
Open redirect
Account takeover
Token leak |
NA |
Ibrahim Auwal (@ibrahimatix0x01) |
Bug Bounty | 2022-08-20 | 2023-06-13 |
1052 | Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library |
Universal XSS
SSRF
Open redirect
Web cache poisoning |
Netlify
Gemini
PancakeSwap
Docusign
Moonpay
Celo |
Sam Curry (@samwcyo) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1045 | My First XSS |
Open redirect
XSS |
NA |
Avyukt Syrine (@AvyuktSyrine) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
993 | Mr. Robot: Self Xss from Informative to high 1200$ ,csrf, open redirect,self xss to stored |
Self-XSS
CSRF |
NA |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
865 | Practical Client Side Path Traversal Attacks |
Path traversal
Client-side Path Traversal
Open redirect
CSS injection |
Acronis |
Medi (@medi_0ne) |
Bug Bounty | 2022-11-04 | 2023-06-13 |
654 | Bypass Apple’s redirection process with the dot (“.”) character |
Open redirect |
Apple |
can1337 (@canmustdie) |
Bug Bounty | 2022-12-24 | 2023-06-13 |
598 | Client-Side SSRF to Google Cloud Project Takeover [Google VRP] |
SSRF
CSRF
Open redirect |
Google |
Dohyun Lee |
Bug Bounty | 2023-01-12 | 2023-06-13 |
480 | Chaining Bugs to get my First Bug Bounty |
CSRF
Open redirect
Clickjacking
Account takeover |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
398 | draw.io CVEs |
SSRF
OAuth
Open redirect
Token leak
Security code review |
draw.io |
@caioluders |
Bug Bounty | 2023-02-24 | 2023-06-13 |
366 | Traveling with OAuth - Account Takeover on Booking.com |
OAuth
Account takeover
Authentication bypass
Open redirect |
Booking.com
KAYAK |
Aviad Carmel (@AviadCarmel) |
Bug Bounty | 2023-03-02 | 2023-06-13 |
357 | GitHub Security Lab audited DataHub: Here’s what they found |
SSRF
Insecure deserialization
Cypher injection
Authentication bypass
Authorization bypass
XSS
Open redirect
JWT
JSON injection
Cryptographic issues
Session expiration issue
Security code review |
DataHub |
Alvaro Muñoz (@pwntester) |
Bug Bounty | 2023-03-03 | 2023-06-13 |