2002 | A story about a not-so-direct SSRF |
SSRF |
NA |
Preetham Bomma (@cyber01_) |
Bug Bounty | 2021-12-12 | 2023-06-13 |
1984 | Bring Your Own SSRF – The Gateway Actuator |
SSRF
DoS |
NA |
Wyatt Dahlenburg (@wdahlenb) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1977 | MS Teams: 1 feature, 4 vulnerabilities |
SSRF
Information disclosure
DoS
Spoofing |
Microsoft |
Fabian Bräunlein |
Bug Bounty | 2021-12-22 | 2023-06-13 |
1971 | Turning bad SSRF to good SSRF: Websphere Portal |
SSRF |
HCL Technologies |
Shubham Shah (@infosec_au) |
Bug Bounty | 2021-12-26 | 2023-06-13 |
1954 | Fixing the Unfixable: Story of a Google Cloud SSRF |
SSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1936 | Exploiting Redash instances with CVE-2021-41192 |
Privilege escalation
Session management issue
SSRF |
NA |
Ian Carroll (@iangcarroll) |
Bug Bounty | 2022-01-06 | 2023-06-13 |
1917 | 120 Days of High Frequency Hunting |
SSRF
LFI
Information disclosure
Broken Access Control
Authentication bypass
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-15 | 2023-06-13 |
1911 | Stealing administrative JWT%27s through post auth SSRF (CVE-2021-22056) |
SSRF
CSRF |
VMware |
Shubham Shah (@infosec_au) |
Bug Bounty | 2022-01-17 | 2023-06-13 |
1906 | The Tale of a Click leading to RCE |
RCE
SSRF |
CatchPoint |
Roni Carta (@0xLupin) |
Bug Bounty | 2022-01-18 | 2023-06-13 |
1901 | 120 Days of Frequent Hacking |
SSRF
LFI
Information disclosure
XSS
SQL injection |
NA |
Kuldeep Pandya (@kuldeepdotexe) |
Bug Bounty | 2022-01-21 | 2023-06-13 |
1885 | Stealing administrative JWT%27s through post auth SSRF (CVE-2021-22056) |
Windows Driver hacking
Kernel DoS |
VMware |
Christopher (@Kharosx0) |
Bug Bounty | 2022-01-27 | 2023-06-13 |
1883 | Bypassing SSRF Protection to Exfiltrate AWS Metadata from LarkSuite |
SSRF |
Lark Technologies |
SirLeeroyJenkins (@SirLeeroyJenkin) |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1880 | Multiple HTTP Redirects to Bypass SSRF Protections |
SSRF |
NA |
ne555 |
Bug Bounty | 2022-01-29 | 2023-06-13 |
1869 | Hacking Google Drive Integrations |
SSRF |
Dropbox |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2022-01-31 | 2023-06-13 |
1839 | CVE-2022-21703: cross-origin request forgery against Grafana |
CSRF
SSRF |
Grafana Labs |
Julien Cretel (@jub0bs) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1834 | Oracle Server Side Request Forgery (SSRF) Metadata |
SSRF |
Oracle |
Lidor Ben Shitrit |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1781 | Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager |
Authentication bypass
RCE
SSRF
Path traversal |
VMware |
Egor Dimitrenko (@elk0kc) |
Bug Bounty | 2022-02-25 | 2023-06-13 |
1780 | SSRF & LFI In Uploads Feature |
SSRF
LFI
HTML injection |
NA |
Raymond Lind |
Bug Bounty | 2022-02-26 | 2023-06-13 |
1759 | Circumventing Browser Security Mechanisms For SSRF |
SSRF
XSS |
NA |
HTTPVoid (@httpvoid0x2f) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1680 | Critical SSRF on Evernote |
SSRF |
Evernote |
Neolex (@NeolexSecurity) |
Bug Bounty | 2022-03-31 | 2023-06-13 |
1668 | Exploiting a double-edged SSRF for server and client-side impact |
SSRF |
NA |
Yassine Aboukir (@Yassineaboukir) |
Bug Bounty | 2022-04-03 | 2023-06-13 |
1666 | Cloud SSRF Exploitation |
SSRF |
NA |
Dan Barros |
Bug Bounty | 2022-04-04 | 2023-06-13 |
1651 | SSRF and Account Takeover via XSS in ERPNext (0-day) |
SSRF
XSS
Account takeover |
ERPNext |
huli (@aszx87410) |
Bug Bounty | 2022-04-06 | 2023-06-13 |
1640 | SVG SSRFs and saga of bypasses |
SSRF
HTML injection |
NA |
Preetham Bomma (@cyber01_) |
Bug Bounty | 2022-04-11 | 2023-06-13 |
1604 | Security issues with cloudflare/odoh-server-go and the ODoH RFC draft |
SSRF |
Cloudflare |
Frans Rosén (@fransrosen) |
Bug Bounty | 2022-04-21 | 2023-06-13 |