3908 | A Simple bypass of Registration Activation that Lead to many Bug - |
Information disclosure
IDOR
CSRF |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-09-21 | 2023-06-13 |
3905 | [Bug Bounty] Exploiting Cookie Based XSS by Finding RCE |
Information disclosure
SQL injection
Authentication bypass
Unrestricted file upload
RCE
XSS |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-09-22 | 2023-06-13 |
3901 | Information Disclosure at PayPal and Xoom (PayPal Acquisition) via Simple Google Dork - 1,000 USD |
Information disclosure |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-09-24 | 2023-06-13 |
3900 | Analysis of CVE-2019-14994 – Jira Service Desk Path Traversal leads to Massive Information Disclosure |
Path traversal |
Atlassian |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-09-25 | 2023-06-13 |
3891 | GraphQL Introspection leads to Sensitive Data Disclosure. |
Information disclosure |
NA |
Pranay Bafna |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3887 | How “Recon” helped Samsung protect their production repositories of SamsungTv, eCommerce / eStores |
Information disclosure |
Samsung |
Prateek Tiwari |
Bug Bounty | 2019-10-05 | 2023-06-13 |
3885 | EXIF Geolocation Data Not Stripped From Uploaded Images |
Information disclosure |
NA |
Sourav Newatia (@souravnewatia) |
Bug Bounty | 2019-10-09 | 2023-06-13 |
3874 | Hunting for bounties antihack.me case study |
RCE
XSS
Logic flaw
Information disclosure |
AntiHack.me |
0xSha (@0xsha) |
Bug Bounty | 2019-10-20 | 2023-06-13 |
3870 | (POC) Disclose members in any closed Facebook group |
Information disclosure |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2019-10-22 | 2023-06-13 |
3867 | How I earned $$$$ by finding confidential customer data including plain-text passwords! |
Directory listing
Information disclosure |
NA |
Sushant Soni (@sushantsoni5392) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3862 | Android Reddit App leaks images |
Information disclosure |
Reddit |
Eric Urban |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3860 | [Leak] Can I take the user information, please?!! |
Information disclosure |
NA |
Mohamed Sayed (@FlEx0Geek) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3856 | GraphQL introspection leads to sensitive data disclosure. |
Information disclosure |
NA |
Eshan Singh (@R0X4R) |
Bug Bounty | 2019-10-30 | 2023-06-13 |
3825 | Million Users PII Leak Data Leak |
Information disclosure
Blind XSS |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2019-11-18 | 2023-06-13 |
3768 | Full Account Takeover (Android Application) |
Information disclosure
Account takeover |
NA |
Vishal Bharad |
Bug Bounty | 2019-12-21 | 2023-06-13 |
3763 | GraphQL IDOR leads to information disclosure |
IDOR |
NA |
Eshan Singh (@R0X4R) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3749 | Facebook Bug bounty Story: $X000 for an Information Disclosure Bug |
Information disclosure |
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2019-12-29 | 2023-06-13 |
3746 | Bug Hunting Journey of 2019 |
XSS
Privilege escalation
Information disclosure |
Alibaba
Yahoo! / Verizon Media |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3712 | Password Reset Token Leak Via Referrer |
Password reset
Information disclosure |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3710 | CORS Misconfiguration leading to Private Information Disclosure |
CORS misconfiguration |
NA |
Virus0X01 (@Virus0X01) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3700 | Tale of a Misconfiguration in Password Reset |
Password reset
Information disclosure |
NA |
Naveenroy |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3697 | How I get my first SWAG from SIDN (Sensitive Data Expose) |
Broken Access Control
Information disclosure |
SIDN |
Mehedi Hasan Remon (@mehedi1194) |
Bug Bounty | 2020-01-29 | 2023-06-13 |
3685 | How, I dumped crypto data by chaining directory listing to open S3 Bucket |
AWS misconfiguration
Directory listing
Information disclosure |
NA |
Ddigvijay |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3681 | How I Made $600 in Bug Bounty in 15 Minutes with Contrast CE – CVE- 2019-8442 |
Information disclosure |
Atlassian |
David Lindner (@golfhackerdave) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3672 | A step-by-step walk-through of an Invalid Endpoint |
Information disclosure |
NA |
Mohammed Israil (@mdisrail2468) |
Bug Bounty | 2020-02-09 | 2023-06-13 |