1463 | [BugTales] UnZiploc: From 0-click To Platform Compromise |
Memory corruption
Logic flaw
RCE
Local Privilege Escalation |
Huawei |
Daniel Komaromy (@kutyacica) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1462 | Privilege Escalation in AKS Clusters |
Privilege escalation |
Microsoft |
Anneke Breust |
Bug Bounty | 2022-06-15 | 2023-06-13 |
1460 | Amazon Linux "log4j hotpatch" <1.3-5 local privilege escalation to root (race condition) |
Local Privilege Escalation |
Amazon |
Justin Steven (@justinsteven) |
Bug Bounty | 2022-06-15 | 2023-06-13 |
1455 | Chaining MFA-Enabled IAM Users with IAM Roles for Potential Privilege Escalation in AWS |
Privilege escalation |
AWS |
Jason Kao |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1445 | Hacking into the worldwide Jacuzzi SmartTub network |
SPA
Android
JWT
Privilege escalation
Mass assignment |
Jacuzzi Group
SmartTub |
Eaton Z. (@XeEaton) |
Bug Bounty | 2022-06-20 | 2023-06-13 |
1419 | FabricScape: Escaping Service Fabric and Taking Over the Cluster |
Container escape
Local Privilege Escalation
Cross-tenant vulnerability |
Microsoft |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1406 | Get root on macOS 12.3.1: proof-of-concepts for Linus Henze%27s CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763) |
Signature validation bypass
Memory corruption
Local Privilege Escalation
MacOS |
Apple |
Zhuowei Zhang (@zhuowei) |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1403 | Vertical Privilege Escalation: The user can takeover an admin account via response manipulation |
Privilege escalation
HTTP response manipulation |
NA |
Jan Muhammad Zaidi (@hasanakajan) |
Bug Bounty | 2022-07-02 | 2023-06-13 |
1400 | We Hacked Larksuite For 1 month and Here is what we found |
XSS
IDOR
Privilege escalation
Broken Access Control
CSRF
40x bypass |
Lark Technologies |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-07-04 | 2023-06-13 |
1399 | Rediscovering Epic Games 0-Days (Forever Unpatched?) |
Local Privilege Escalation |
Epic Games |
Christopher Vella (@Kharosx0) |
Bug Bounty | 2022-07-06 | 2023-06-13 |
1394 | Interesting Privilege Escalation In an Old Private Program |
Privilege escalation |
NA |
Zunaid Mahmud (@SZ_Mahmud_7) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1383 | Exploiting Authentication in AWS IAM Authenticator for Kubernetes |
Authentication flaw
Privilege escalation |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2022-07-11 | 2023-06-13 |
1377 | Microsoft Azure Site Recovery DLL Hijacking |
DLL Hijacking
Privilege escalation |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1376 | CVE-2022-32223 Discovery: DLL Hijacking via npm CLI |
DLL Hijacking
Privilege escalation |
Node.js |
Yakir Kadkoda |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1371 | Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706 |
Local Privilege Escalation |
Apple |
Microsoft 365 Defender Research Team |
Bug Bounty | 2022-07-13 | 2023-06-13 |
1362 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
Lack of rate limiting
Privilege escalation
IDOR
Account takeover |
NA |
Muhammad Talha / evilmango |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1360 | Ability to login as google staff in Google Cloud Community |
Privilege escalation |
Google |
Gaurav Bhatia |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1345 | Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass |
Local Privilege Escalation |
OPC Foundation |
Sector 7 (@sector7_nl) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1343 | Logging Passwords in Plaintext in Azure Arc |
Information disclosure
Local Privilege Escalation
Cloud |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1341 | CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation |
Local Privilege Escalation |
Zyxel |
Jake Baines (@Junior_Baines) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1336 | [CVE-2022-34918] A crack in the Linux firewall |
Memory corruption
Local Privilege Escalation |
Linux Kernel Organization |
Arthur Mongodin |
Bug Bounty | 2022-07-20 | 2023-06-13 |
1320 | Deep understand ASPX file handling and some related attack vectors |
Local Privilege Escalation
WAF bypass |
Microsoft |
Rskvp93 (@rskvp93) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1293 | My Second CVE (CVE-2022-31855) |
OS command injection
Local Privilege Escalation |
RStudio |
y0ung_dst (@Y0ung_MA) |
Bug Bounty | 2022-07-30 | 2023-06-13 |
1285 | Multiple bugs in one program leads to 1500€ |
Privilege escalation
IDOR
Authorization flaw |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1281 | Hijacking email with Cloudflare Email Routing |
HTTP response manipulation
Privilege escalation |
NA |
Albert Pedersen (@AlbertSPedersen) |
Bug Bounty | 2022-08-03 | 2023-06-13 |