1206 | Let%27s Dance in the Cache - Destabilizing Hash Table on Microsoft IIS! |
DoS
Web cache poisoning
Authentication bypass |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1199 | Account takeover worth $1000 |
Account takeover
Authentication bypass
Information disclosure
Password reset |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1100 | Riding The Inforail To Exploit Ivanti Avalanche Part 2 |
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read |
Ivanti |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
1097 | How I was able to Bypass Philips Authentication |
Outdated component with a known vulnerability
Authentication bypass |
Philips |
ParagBagul |
Bug Bounty | 2022-09-10 | 2023-06-13 |
1044 | My First Valid Bug “Bypass the Admin Panel” |
Authentication bypass |
NA |
Digant Prajapati |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1023 | Exploits Explained: 5 Unusual Authentication Bypass Techniques |
Authentication bypass
JWT
CMS
SSO |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2022-09-28 | 2023-06-13 |
1000 | How I Found A P1 Bug |
Authentication bypass
Information disclosure |
NA |
Amith |
Bug Bounty | 2022-10-05 | 2023-06-13 |
963 | FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive (CVE-2022-40684) |
Authentication bypass |
Fortinet |
James Horseman (@JamesHorseman2) |
Bug Bounty | 2022-10-13 | 2023-06-13 |
954 | Google SSO misconfiguration leading to Account Takeover |
Authentication bypass
Account takeover
SSO |
NA |
0x4KD (@0x4kd) |
Bug Bounty | 2022-10-14 | 2023-06-13 |
930 | 23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite |
JWT
Authentication bypass
Arbitrary file write
Unrestricted file upload |
NA |
Souhaib Naceri (@h4x0r_dz) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
846 | Accidental $70k Google Pixel Lock Screen Bypass |
Lock screen bypass
Authentication bypass
Android |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-10 | 2023-06-13 |
828 | Checkmk: Remote Code Execution by Chaining Multiple Bugs (1/3) |
RCE
Code injection
SSRF
Line Feed injection
Arbitrary file read
Authentication bypass
Security code review |
Checkmk |
Stefan Schiller (@scryh_) |
Bug Bounty | 2022-11-15 | 2023-06-13 |
784 | From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942) |
Authentication bypass
Kerberos
RCE
Privilege escalation
Security code review |
Intel |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
768 | Access Any Owner Account without Authentication (Auth bypass + 2FA bypass) |
Authentication bypass
MFA bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
765 | 2FA Enabled Accounts Can Bypass Authentication & Access Account After Deactivation |
Authentication bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
678 | Better Make Sure Your Password Manager Is Secure |
Hardcoded credentials
XSS
Cryptographic issues
Authorization flaw
Authentication bypass |
Click Studios |
kuekerino (@kuekerino) |
Bug Bounty | 2022-12-19 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
650 | Authentication Bypass in Nexus manager (version 3.37.3–02) |
Components with known vulnerabilities
Authentication bypass
HTTP response manipulation |
NA |
SHARAN.K |
Bug Bounty | 2022-12-26 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
620 | Cacti: Unauthenticated Remote Code Execution |
RCE
Authentication bypass
OS command injection
Security code review |
Cacti |
Stefan Schiller (@scryh_) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
619 | CVE-2022-25026 & CVE-2022-25027: Vulnerabilities in Rocket TRUfusion Enterprise |
Authentication bypass
SSRF |
Rocket Software |
Tom Wedgbury |
Bug Bounty | 2023-01-04 | 2023-06-13 |
591 | YAFPC — Unauthenticated Remote Code Execution |
Authentication bypass
Hardcoded credentials
RCE |
NA |
Luke Paris |
Bug Bounty | 2023-01-14 | 2023-06-13 |
579 | Centreon map vulnerability |
Authentication bypass |
Centreon |
Vladimir |
Bug Bounty | 2023-01-17 | 2023-06-13 |
564 | Two Factor Authentication Bypass On Facebook |
MFA bypass |
Meta / Facebook |
Gtm Mänôz (@Gtm0x01) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
549 | Using 0days to Protect the United Nations |
RCE
Authentication bypass
Path traversal |
United Nations |
Florian Hauser (@frycos) |
Bug Bounty | 2023-01-24 | 2023-06-13 |