3798 | Google Chrome portal element fuzzing |
RCE
Memory corruption
Buffer Overflow
Use-After-Free |
Google |
Pawel Wylecial (@h0wlu) |
Bug Bounty | 2019-12-06 | 2023-06-13 |
3793 | Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution. |
RCE |
Telegram |
Vladimir Metnew (@vladimir_metnew) |
Bug Bounty | 2019-12-08 | 2023-06-13 |
3779 | 4 Google Cloud Shell bugs explained |
RCE |
Google |
wtm@offensi.com (@wtm_offensi) |
Bug Bounty | 2019-12-16 | 2023-06-13 |
3773 | Javascript Anti Debugging - Abusing SourceMappingURL |
Browser hacking |
Google (Chromium) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2019-12-17 | 2023-06-13 |
3771 | #BugBounty — How Snapdeal (India’s Popular E-commerce Website) Kept their Users Data at Risk! |
Insecure storage of sensitive information |
Snapdeal |
Nanda Kumar (@nk00_nk) |
Bug Bounty | 2019-12-19 | 2023-06-13 |
3760 | How we hacked one of the worlds largest Cryptocurrency Website |
SQL injection
RCE |
NA |
Strynx (@Strynx_Security) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3759 | Abusing ImageMagick to obtain RCE |
ImageTragick
RCE |
NA |
Strynx (@Strynx_Security) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3757 | Microsoft Edge (Chromium) - EoP via XSS to Potential RCE |
XSS
RCE |
Microsoft |
Abdulrahman Alqabandi (@Qab) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3739 | Exploiting Wi-Fi Stack on Tesla Model S |
Wifi hacking
Driver hacking
RCE
Memory corruption |
Tesla |
Tencent Keen Security Lab |
Bug Bounty | 2020-01-02 | 2023-06-13 |
3735 | How I found a Privilege Escalation Bug in a private Ecommerce? |
Privilege escalation |
NA |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-01-06 | 2023-06-13 |
3728 | My First RCE (Stressed Employee gets me 2x bounty) |
Unrestricted file upload
RCE |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-01-10 | 2023-06-13 |
3724 | Pwning Avast Secure Browser for fun and profit |
RCE
Command injection |
Avast |
Wladimir Palant (@WPalant) |
Bug Bounty | 2020-01-13 | 2023-06-13 |
3721 | The trouble with Microsoft’s Troubleshooters |
RCE
MiTM |
Microsoft |
Imre Rad (@ImreRad) |
Bug Bounty | 2020-01-15 | 2023-06-13 |
3688 | Responsible Disclosure: Breaking out of a Sandboxed Editor to perform RCE |
RCE |
HackerEarth |
Jatin Dhankhar (@jatindhankhar_) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3687 | Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File System Access |
Stored XSS
CSP bypass
Open redirect
RCE |
Meta / Facebook |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3678 | Simple Remote Code Execution Vulnerability Examples for Beginners |
RCE
Unrestricted file upload |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3676 | How Inspect Element Got me a Bounty |
Client-side enforcement of server-side security |
NA |
Aditya Soni (@hetroublemakr) |
Bug Bounty | 2020-02-06 | 2023-06-13 |
3675 | IDOR leads to Data leakage and Profile Update |
IDOR
Bruteforce |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-02-07 | 2023-06-13 |
3668 | CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE |
RCE
Stored XSS
CSP bypass
Arbitrary file read
Open redirect
Security code review |
Meta / Facebook (WhatsApp) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-14 | 2023-06-13 |
3664 | Uploading Backdoor For Fun And Profit. |
Unrestricted file upload
RCE |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3658 | From Recon to Optimizing RCE Results – Simple Story with One of the Biggest ICT Company in the World |
Information disclosure
RCE |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3657 | A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell |
XXE
RCE
Directory Traversal |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3643 | RCE via Apache Struts2 - Still out there. |
RCE |
NA |
Abhishek (@abhishake100) |
Bug Bounty | 2020-02-27 | 2023-06-13 |
3632 | ManageEngine ServiceDesk Plus: Arbitrary File Upload |
Arbitrary file upload
RCE |
NA |
Duc Anh Bui |
Bug Bounty | 2020-03-03 | 2023-06-13 |
3620 | Broke limited scope with a chain of bugs (tips for every rider CORS) |
CORS misconfiguration
RCE |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2020-03-09 | 2023-06-13 |