548 | Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI |
RCE
Authentication bypass
Security code review
JWT |
Yellowfin BI |
Maxwell Garrett (@TheGrandPew) |
Bug Bounty | 2023-01-24 | 2023-06-13 |
539 | How I Found My First Bug in Android App |
Android
Authentication bypass
Insecure intent |
NA |
Barath Stalin |
Bug Bounty | 2023-01-26 | 2023-06-13 |
511 | CentreStack Disclosure |
Authentication bypass
Password reset
Unrestricted file upload
RCE |
Gladinet (CentreStack) |
Michael Rand |
Bug Bounty | 2023-02-02 | 2023-06-13 |
499 | Authentication Bypass in Izanami Docker image 1.10.22 CVE-2023-22495 |
Authentication bypass
JWT
Security code review
Container security |
Izanami |
Raphaël Lob |
Bug Bounty | 2023-02-03 | 2023-06-13 |
490 | Hacking into Toyota’s global supplier management network |
Authentication bypass
Backdoor |
Toyota |
Eaton Z. (@XeEaton) |
Bug Bounty | 2023-02-06 | 2023-06-13 |
458 | Hacking our way into internal DBs with hardcoded authentication keys |
JWT
SSO
Authentication bypass
Security misconfiguration |
NA |
Ophion Security (@OphionSecurity) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
444 | Technical Advisory – Azure B2C – Crypto Misuse and Account Compromise |
Cryptographic issues
JWT
Account takeover
Authentication bypass |
Microsoft (Azure) |
John Novak |
Bug Bounty | 2023-02-15 | 2023-06-13 |
429 | Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover |
Account takeover
SSO
OTP
Authentication bypass |
NA |
Aidil Arief |
Bug Bounty | 2023-02-20 | 2023-06-13 |
374 | How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability? |
Account takeover
Authentication bypass |
NA |
Vivek Kumar Yadav (@0xd3vil) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
366 | Traveling with OAuth - Account Takeover on Booking.com |
OAuth
Account takeover
Authentication bypass
Open redirect |
Booking.com
KAYAK |
Aviad Carmel (@AviadCarmel) |
Bug Bounty | 2023-03-02 | 2023-06-13 |
357 | GitHub Security Lab audited DataHub: Here’s what they found |
SSRF
Insecure deserialization
Cypher injection
Authentication bypass
Authorization bypass
XSS
Open redirect
JWT
JSON injection
Cryptographic issues
Session expiration issue
Security code review |
DataHub |
Alvaro Muñoz (@pwntester) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
345 | Authentication Bypass Vulnerability in Mura CMS and Masa CMS (CVE-2022-47003 and CVE-2022-47002) |
Authentication bypass
Security code review
ColdFusion |
Mura CMS
Masa CMS |
Brian (@hoyahaxa) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
344 | Insecure Toyota CRM exposed Mexican customer information |
Authentication bypass |
Toyota |
Eaton Z. (@XeEaton) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
342 | Remote Stealth Brute-force of Oracle Database Passwords |
Bruteforce
Information disclosure
Authentication bypass
Components with known vulnerabilities |
NA |
Viktor Markopoulos |
Bug Bounty | 2023-03-06 | 2023-06-13 |
336 | [Account Takeover] Don’t Send a Message to anyone Before Reading This [External Audit] |
HTTP response manipulation
Authentication bypass
Account takeover |
NA |
Vipul Sahu |
Bug Bounty | 2023-03-07 | 2023-06-13 |
318 | CVE-2022-36413 Unauthorized Reset Password of Zoho ManageEngine ADSelfService Plus |
Password reset
OTP bruteforce
Account takeover
Authentication bypass |
Zoho (ManageEngine) |
Sky |
Bug Bounty | 2023-03-10 | 2023-06-13 |
215 | How I was able to change password of any corporate user |
Account takeover
Password reset
Authentication bypass |
NA |
CH3TAN |
Bug Bounty | 2023-04-09 | 2023-06-13 |
207 | SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication (CVE-2023-22620) |
Authentication bypass |
SecurePoint |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
191 | A Big company Admin Panel takeover $4500 |
Authentication bypass
40x bypass
Account takeover |
NA |
nanwn |
Bug Bounty | 2023-04-17 | 2023-06-13 |
190 | Multiple Critical Vulnerabilities In Strapi Versions <=4.7.1 |
Authentication bypass
SSTI
RCE
Amazon cognito misconfiguration
Information disclosure |
Strapi |
GhostCcamm (@GhostCcamm) |
Bug Bounty | 2023-04-17 | 2023-06-13 |
163 | How careless default credentials impact to massive account takeover |
Authentication bypass
Account takeover
Weak credentials |
NA |
M Maulana Abdullah |
Bug Bounty | 2023-04-22 | 2023-06-13 |
148 | Redash SAML Authentication Bypass |
SAML
Authentication bypass |
Redash |
An Trinh (@_tint0) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
109 | PwnAssistant - Controlling /home%27s Via A Home Assistant RCE |
Authentication bypass
RCE
Security code review
IoT |
Home Assistant |
elttam (@elttam) |
Bug Bounty | 2023-05-09 | 2023-06-13 |
103 | What is kong & why we’re relying on it |
RCE
Sandbox escape
Authentication bypass
Hardcoded credentials
Broken Access Control
Privilege escalation
JWT |
Konga |
Laluka (@TheLaluka) |
Bug Bounty | 2023-05-10 | 2023-06-13 |