989 | CVE-2022–36635 — A SQL Injection in ZKSecurityBio to RCE |
SQL injection |
ZKTeco |
Caio Burgardt (@CaioBurgardt) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
965 | SQL Injection in GraphQL |
SQL injection
GraphQL |
NA |
Ahmed Gad (@0xGAD) |
Bug Bounty | 2022-10-13 | 2023-06-13 |
958 | Code Injection and SQLi in WP ALL Export Pro |
SQL injection
Security code review |
NA |
p3n7a90n (@p3n7a90n) |
Bug Bounty | 2022-10-14 | 2023-06-13 |
956 | The Castle’s Latrine |
SQL injection |
NA |
infiltrateops |
Bug Bounty | 2022-10-14 | 2023-06-13 |
913 | Remote Code Execution by Abusing Apache Spark SQL |
SQL injection
RCE |
NA |
Colin McQueen |
Bug Bounty | 2022-10-24 | 2023-06-13 |
882 | Blind SQL Injection on Delete Request |
Blind SQL injection |
NA |
Jawad Mahdi (@hunter0x1) |
Bug Bounty | 2022-10-30 | 2023-06-13 |
875 | Fuzzing For Hidden Params |
SQL injection |
NA |
calfcrusher |
Bug Bounty | 2022-11-02 | 2023-06-13 |
848 | Sleep SQL injection on Name Parameter While Updating Profile |
SQL injection |
NA |
Umer Yousuf |
Bug Bounty | 2022-11-10 | 2023-06-13 |
832 | SSD Advisory – Cisco Secure Manager Appliance remediation_request_utils SQL Injection Remote Code Execution |
SQL injection
RCE
Security code review |
Cisco |
- |
Bug Bounty | 2022-11-14 | 2023-06-13 |
827 | Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk |
SQL injection
Logic flaw |
Zendesk |
Tal Peleg |
Bug Bounty | 2022-11-15 | 2023-06-13 |
788 | How I get +10 SQLi and +30 XSS via Automation Tool |
SQL injection
XSS |
NA |
Mahmoud Attia (@0xElkot) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
786 | CVE-2022-40300: SQL Injection In Manageengine Privileged Access Management |
SQL injection |
Zoho (ManageEngine) |
Justin Hung |
Bug Bounty | 2022-11-23 | 2023-06-13 |
772 | A great weekend hack(worth $8k) |
SQL injection
IDOR
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
749 | Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access |
Cloud
SQL injection
Privilege escalation
Information disclosure |
IBM |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
746 | From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225) |
SQL injection
Kerberos
RCE
Privilege escalation
Security code review |
Intel |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-12-01 | 2023-06-13 |
721 | A03:2021 — [Injection] SQL Injection through internal directory disclose |
SQL injection
Information disclosure |
NA |
Tushar |
Bug Bounty | 2022-12-07 | 2023-06-13 |
717 | {JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF |
WAF bypass
SQL injection |
Palo Alto Networks
AWS
Cloudflare
F5
Imperva |
Noam Moshe |
Bug Bounty | 2022-12-08 | 2023-06-13 |
698 | Exploiting an SQL injection with WAF bypass |
SQL injection
WAF bypass |
NA |
Benoit Philippe |
Bug Bounty | 2022-12-13 | 2023-06-13 |
696 | How I Hacked A Company (My First Red Team Engagement 🚩)Permalink |
SQL injection |
NA |
Monish Kumar (@aidenpearce369) |
Bug Bounty | 2022-12-13 | 2023-06-13 |
661 | Multiple authenticated blind SQL Injections in Sage XRT Business Exchange application |
Blind SQL injection |
Sage |
Mickaël Benassouli (@mickaelweb) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
648 | How I found multiple critical bugs in Red Bull |
Authentication bypass
HTTP response manipulation
Path traversal
LFI
XSS
SQL injection
RCE
Unrestricted file upload
RFI
Security code review |
Red Bull |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-12-26 | 2023-06-13 |
639 | Getting Secret Key to Building Custom Burp Extension |
SQL injection |
NA |
Ashlyn Lau |
Bug Bounty | 2022-12-29 | 2023-06-13 |
635 | CVE-2022-38627: A journey through SQLite Injection to compromise the whole enterprise building |
SQL injection |
NA |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2022-12-30 | 2023-06-13 |
621 | Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More |
Account takeover
SSO
RCE
Authorization bypass
SQL injection
Mass assignment
Information disclosure |
Kia
Honda
Infiniti
Nissan
Acura
Mercedes-Benz
Hyundai
Genesis
BMW
Rolls Royce
Ferrari
Spireon
Ford
Reviver
Porsche
Toyota
Jaguar
Land Rover
SiriusXM |
Sam Curry (@samwcyo) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
588 | thisclosed_#2 - PostgreSQL Database Exfiltration through the abuse of PostgREST requests |
SQL injection |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2023-01-16 | 2023-06-13 |