3715 | Google Bug Bounty: CSRF in learndigital.withgoogle.com |
CSRF |
Google |
santuySec (@santuySec) |
Bug Bounty | 2020-01-21 | 2023-06-13 |
3714 | User Account Takeover via Signup Feature | Bug Bounty POC |
Account takeover
Logic flaw
Authorization flaw |
NA |
Muzammil Kayani (@muzammilabbas2) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3713 | Facebook Vulnerability: Hidden “Community Manager” in Pages due to “Invitation Accept” logic |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3712 | Password Reset Token Leak Via Referrer |
Password reset
Information disclosure |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3711 | A Less Known Attack Vector, Second Order IDOR Attacks |
IDOR |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-01-22 | 2023-06-13 |
3710 | CORS Misconfiguration leading to Private Information Disclosure |
CORS misconfiguration |
NA |
Virus0X01 (@Virus0X01) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3709 | How I was able to take over any users account with host header injection |
Host header injection |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3707 | The unexpected bounty: A story of Zendesk takeover on REDACTED.com |
Subdomain takeover |
NA |
wis4nggeni |
Bug Bounty | 2020-01-25 | 2023-06-13 |
3706 | Accidental IDOR that Deleted Admin Account. |
IDOR |
NA |
Sayaan Alam (@ehsayaan) |
Bug Bounty | 2020-01-25 | 2023-06-13 |
3705 | Improper Input Validation | Add Custom Text and URLs In SMS send by Snapchat | Bug Bounty POC |
Parameter tampering |
Meta / Facebook |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-01-26 | 2023-06-13 |
3701 | Escalating reflected XSS with HTTP Smuggling |
Reflected XSS
HTTP request smuggling |
NA |
Hazana (@HazanaSec) |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3700 | Tale of a Misconfiguration in Password Reset |
Password reset
Information disclosure |
NA |
Naveenroy |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3699 | Adding anyone including non-friend and blocked people as co-host in personal event! |
IDOR |
Meta / Facebook |
Binit Ghimire (@WHOISbinit) |
Bug Bounty | 2020-01-28 | 2023-06-13 |
3698 | Hyperlink Injection - Easy Money (sometimes) |
Hyperlink injection |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-01-28 | 2023-06-13 |
3697 | How I get my first SWAG from SIDN (Sensitive Data Expose) |
Broken Access Control
Information disclosure |
SIDN |
Mehedi Hasan Remon (@mehedi1194) |
Bug Bounty | 2020-01-29 | 2023-06-13 |
3696 | How I was able to takeover the company’s LinkedIn Page |
Broken link hijacking |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-01-29 | 2023-06-13 |
3695 | 2FA Bypass via Logical Rate Limiting Bypass |
MFA bypass
Logic flaw |
NA |
Jeppe Bonde Weikop |
Bug Bounty | 2020-01-30 | 2023-06-13 |
3694 | OK Google: bypass the authentication! |
Authentication bypass |
Google |
Mattia Vinci |
Bug Bounty | 2020-01-31 | 2023-06-13 |
3692 | Tumblr Bug Bounty ( $200) |
Unrestricted file upload
XSS
Authorization flaw |
Automattic |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-02 | 2023-06-13 |
3691 | CSRF CSRF CSRF… |
CSRF |
NA |
Navneet (@na5n33t) |
Bug Bounty | 2020-02-03 | 2023-06-13 |
3690 | Easily leaking passenger information on an Airline |
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3689 | Exploiting Insecure Firebase Database! |
Insecure Firebase database
Android |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3688 | Responsible Disclosure: Breaking out of a Sandboxed Editor to perform RCE |
RCE |
HackerEarth |
Jatin Dhankhar (@jatindhankhar_) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3687 | Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File System Access |
Stored XSS
CSP bypass
Open redirect
RCE |
Meta / Facebook |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3686 | Arbitary File Upload too Stored XSS - Bug Bounty |
Arbitrary file upload
Stored XSS |
NA |
m0chan (@m0chan98) |
Bug Bounty | 2020-02-04 | 2023-06-13 |