3576 | CVE-2019-17004—Semi Universal XSS affecting Firefox for iOS |
Universal XSS |
Mozilla
Brave Software |
cliqz (@cliqz) |
Bug Bounty | 2020-03-30 | 2023-06-13 |
3575 | Restriction is not a promise : Privilege escalation on Google. |
Privilege escalation
Authorization flaw |
Google |
Hariharan.s (@DJHARIZ1) |
Bug Bounty | 2020-03-30 | 2023-06-13 |
3574 | Limited freemarker ssti to arbitrary liql query and manage lithium cms |
SSTI |
NA |
Mert (@mertistaken) |
Bug Bounty | 2020-03-30 | 2023-06-13 |
3573 | Hacking makes me forget my pain |
SQL injection |
NA |
Abida Fahd |
Bug Bounty | 2020-03-31 | 2023-06-13 |
3572 | Akamai Web Application Firewall Bypass Journey: Exploiting “Google BigQuery” SQL Injection Vulnerability |
SQL injection |
NA |
Duc Nguyen (@ducnt_) |
Bug Bounty | 2020-03-31 | 2023-06-13 |
3571 | Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC |
RCE |
Microsoft |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-03-31 | 2023-06-13 |
3570 | $3133.7 Google Bug Bounty Writeup- XSS Vulnerability! |
Reflected XSS |
Google |
Pethuraj (@Pethuraj) |
Bug Bounty | 2020-04-01 | 2023-06-13 |
3569 | The story of my first ever, 1500$, bounty from Facebook. |
Logic flaw |
Meta / Facebook |
Ashok Chapagai (@ashokcpg) |
Bug Bounty | 2020-04-01 | 2023-06-13 |
3568 | Privilege Escalation - Hello Admin |
Privilege escalation |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3567 | Account Take Over without user Interaction |
Password reset
Information disclosure
Account takeover |
NA |
Ravilla Bharath |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3566 | Always escalate! From Self-XSS to Persistent XSS on Login Portal |
Self-XSS
CSRF |
NA |
Phuriphat Boontanon (@zanezenzane) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3565 | Hundreds of internal servicedesks exposed due to COVID-19 |
Security misconfiguration |
NA |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3564 | iPhone Camera Hack |
Zero-Click Unauthorized Access to Sensitive Data |
Apple |
Ryan Pickren |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3563 | Touch ID Authentication Bypass on Evernote and Dropbox IOS Apps |
Authentication bypass
iOS |
Evernote
Dropbox |
Sahil Tikoo (@viperbluff) |
Bug Bounty | 2020-04-03 | 2023-06-13 |
3562 | Playing with JSON Web Tokens for Fun and Profit |
Password reset
Email verification bypass |
NA |
Muhammad Qasim Munir (@MeetAn0nym0us) |
Bug Bounty | 2020-04-04 | 2023-06-13 |
3561 | Cannot Delete Post on Facebook Group: Facebook Bug Bounty |
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-04-04 | 2023-06-13 |
3560 | Page Admin Disclosure: Facebook Bug Bounty 2020 |
Information disclosure
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-04-04 | 2023-06-13 |
3559 | How a Simple CSRF Attack Turned into a P1 Level Bug |
CSRF
Account takeover |
NA |
Lady Secspeare (@bejuveria_) |
Bug Bounty | 2020-04-05 | 2023-06-13 |
3558 | How we abused Slack%27s TURN servers to gain access to internal services |
SSRF |
Slack |
Sandro Gauci (@sandrogauci) |
Bug Bounty | 2020-04-06 | 2023-06-13 |
3557 | $3K Bounty For Elastic-Search Takeover |
Elasticsearch Takeover
Information disclosure |
NA |
Ashish Kunwar (@D0rkerDevil) |
Bug Bounty | 2020-04-06 | 2023-06-13 |
3556 | Stored XSS in Google Nest |
Stored XSS |
Google |
Harikrishnan Chandraganesan (@hari_cybex) |
Bug Bounty | 2020-04-07 | 2023-06-13 |
3555 | Unrestricted CV File Upload |
Unrestricted file upload |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-04-07 | 2023-06-13 |
3554 | Listing all registered email addresses on Google’s Crisis Map thanks to IDOR and incremental IDs |
IDOR |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2020-04-07 | 2023-06-13 |
3553 | The story of a fuzzing integration reward |
Memory corruption |
Google |
Andrea Brancaleoni (@nJoyneer) |
Bug Bounty | 2020-04-08 | 2023-06-13 |
3552 | How i Unlocked the blocked accounts? |
Password reset
HTTP parameter pollution
IDOR |
NA |
Maria Zulfiqar |
Bug Bounty | 2020-04-11 | 2023-06-13 |