1691 | Pwning Microsoft Azure Defender for IoT | Multiple Flaws Allow Remote Code Execution for All |
RCE
Memory corruption
SQL injection |
Microsoft |
Kasif Dekel (@kasifdekel) |
Bug Bounty | 2022-03-28 | 2023-06-13 |
1663 | NoSQL Injection in Plain Sight |
NoSQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-04-04 | 2023-06-13 |
1661 | CVE-2021-38159: MOVEit Transfer SQL Injection Analysis |
SQL injection |
Palantir Public |
Tuan Anh Nguyen (@haxor31337) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1655 | CVE-2021-4119: [Bookstack] Email harvesting via SQL "LIKE" clause exploitation |
Broken Access Control
SQL injection |
Bookstack |
Haxatron (@Haxatron1) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1647 | How a YouTube Video lead to pwning a web application via SQL Injection worth $4324 bounty |
SQL injection |
NA |
Vishal Saini (@k4k4r07) |
Bug Bounty | 2022-04-08 | 2023-06-13 |
1614 | SQL Injection in Harvard’s Subdomain |
SQL injection |
Harvard |
Bibek Neupane (@nb1b3k) |
Bug Bounty | 2022-04-17 | 2023-06-13 |
1572 | Advanced sqlmap Case Study |
SQL injection |
NA |
Peter M (@h1pmnh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1540 | Gaining access through error-based SQLi using WebSockets |
SQL injection
Websockets
Password reset |
NA |
Bitcrack (@bitcrack_cyber) |
Bug Bounty | 2022-01-12 | 2023-06-13 |
1539 | Research: Auditing WordPress Plugins |
SQL injection
LFI
XSS
RCE |
NA |
cy//ective (@cyllective) |
Bug Bounty | 2022-05-20 | 2023-06-13 |
1515 | A Simple SQL Injection in an Air Force Website |
SQL injection |
U.S. Dept Of Defense |
Corben Leo (@hacker_) |
Bug Bounty | 2022-05-27 | 2023-06-13 |
1505 | SQL injection to Remote Command Execution (RCE) |
SQL injection
RCE |
NA |
Kwadwo Amoako |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1396 | CVE-2022-34265 |
SQL injection |
Django |
Takuto Yoshikai (@TakutoYoshikai) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1388 | Advisory | GLPI Service Management Software Multiple Vulnerabilities and Remote Code Execution |
SQL injection
RCE
LFI |
GLPI |
Nuri Çilengir (@ncilengir) |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1385 | Exploiting SQL Injection at Authorization token |
SQL injection
Account takeover |
NA |
Basudev |
Bug Bounty | 2022-07-09 | 2023-06-13 |
1375 | Leveraging the SQL Injection to Execute the XSS by Evading CSP |
CSP bypass
SQL injection
XSS |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1328 | WordPress Transposh: Exploiting a Blind SQL Injection via XSS - RCE Security |
SQL injection
XSS
Account takeover |
WordPress |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1284 | (ZOHO) Manage Engine Desktop Central – SQL Injection / Arbitrary File Write |
SQL injection
Arbitrary file write
Path traversal |
Zoho |
Tom Ellson (@tde_sec) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1265 | Dancing on the architecture of VMware Workspace ONE Access (ENG) |
Authentication bypass
SQL injection
RCE |
VMware |
Petrus Viet (@VietPetrus) |
Bug Bounty | 2022-08-09 | 2023-06-13 |
1204 | Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets? |
Robotic Process Automation
Insecure deserialization
SQL injection
MiTM |
Blue Prism |
Nimrod Stoler (@n1mr0d5) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1156 | Found SQL Injection Vulnerability on Government Organization Website! |
SQL injection |
NA |
mehedishakeel (@mehedishakeel) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1140 | How can i get SQL Injection |
SQL injection |
NA |
Mohamed Abdelhady |
Bug Bounty | 2022-09-02 | 2023-06-13 |
1087 | Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover |
Blind XSS
SQL injection |
NA |
Cyberali |
Bug Bounty | 2022-09-13 | 2023-06-13 |
1054 | TypeORM Prototype Pollution Leading To SQL Injection (CVE-2022-36531) |
DoS
SQL injection |
TypeORM |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1049 | How I Found Multiple SQL Injections in 5 Minutes in Bug Bounty |
SQL injection |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-09-22 | 2023-06-13 |
996 | Error based SQL Injection with WAF bypass manual Exploit 100% |
SQL injection
WAF bypass |
NA |
Ahmed Qaramany (@c0nqr0r) |
Bug Bounty | 2022-10-06 | 2023-06-13 |