2911 | How I was able to Regain access to account deleted by Admin leading to $$$ |
Logic flaw
Authorization flaw |
NA |
Rajesh Ranjan (@_rajesh_ranjan_) |
Bug Bounty | 2021-01-10 | 2023-06-13 |
2898 | Tale of 2 TOOTB Bugs: Google and WhatsApp |
Information disclosure
Logic flaw |
Google
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2897 | Irremovable Facebook group album photos and entire album under certain circumstances (Bounty: 1000 USD) |
Logic flaw |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2883 | Simple & Sweet: Bypass email update restriction to change emails of team members |
Logic flaw
Authorization flaw |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2873 | $10,000 for automatic email confirmation bug in Microsoft’s Edge browser |
Logic flaw |
Microsoft |
Karan Chaudhary (@0xKaran) |
Bug Bounty | 2021-01-23 | 2023-06-13 |
2859 | Business Logic Error Methodology (easy way) + PoC-s |
Logic flaw |
NA |
Vuk Ivanovic |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2823 | A Tale of 2nd $xxx Bounty from Facebook |
Logic flaw |
Meta / Facebook |
Kunjan Nayak |
Bug Bounty | 2021-02-10 | 2023-06-13 |
2816 | How I was able to get extra coins |
Logic flaw
Android |
NA |
Saddam Hussain (@wisdomfreak1) |
Bug Bounty | 2021-02-12 | 2023-06-13 |
2761 | Story About Stop 10000+ users to get Their job notification |
Logic flaw |
NA |
PJBorah |
Bug Bounty | 2021-02-27 | 2023-06-13 |
2744 | The Invincible Kid |
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2741 | Low hanging fruits on Facebook Group Room. Unable to remove post on group when post room add with event ($500) |
Logic flaw |
Meta / Facebook |
Randy Arios |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2709 | Stealing arbitrary GitHub Actions secrets |
Logic flaw |
GitHub |
Teddy Katz (@not_aardvark) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2704 | How to Harpon Big Blue! |
Logic flaw
Exposed registration page |
IBM |
Clark Voss (@clark_voss) |
Bug Bounty | 2021-03-19 | 2023-06-13 |
2692 | PoC: The easiest 125 Euro’s I Ever made |
Logic flaw |
NA |
Thexssrat (@theXSSrat) |
Bug Bounty | 2021-03-25 | 2023-06-13 |
2688 | How to bypass CloudFlare bot protection ? |
Logic flaw |
Cloudflare |
jychp (@jychp_fr) |
Bug Bounty | 2021-03-27 | 2023-06-13 |
2680 | My first Bug report at Facebook 2021 |
Logic flaw
Authorization flaw |
Meta / Facebook |
Kent Jarold Abulag (@wkemenhehehegsg) |
Bug Bounty | 2021-03-31 | 2023-06-13 |
2668 | Gain write permission of repositories with a bug in GitHub Actions |
Broken Access Control
Logic flaw |
GitHub |
tyage (@tyage) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2655 | What if you could deposit money into your Betting account for free? Oh wait where has this 25k came from… |
Logic flaw |
NA |
Mikey (@mikey96_bh) |
Bug Bounty | 2021-04-07 | 2023-06-13 |
2653 | Auth Issues |
Authentication flaw
Logic flaw |
Google |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2021-04-09 | 2023-06-13 |
2636 | Lets Learn English - Hacking 10M+ Users |
AWS misconfiguration
Insecure Firebase database
OTP bypass
Account takeover
Logic flaw |
NA |
Aseem Shrey (@AseemShrey) |
Bug Bounty | 2021-04-17 | 2023-06-13 |
2635 | (POC) Remove any Facebook’s live video ($14,000 bounty) |
Logic flaw |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2021-04-17 | 2023-06-13 |
2632 | Misconfiguration in Change-password Functionality Leads to Account Takeover |
IDOR
Logic flaw
Password reset
Account takeover |
NA |
Mahmoud Radwan (@0x___2m) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2625 | IDOR leads to leaked the likes count even though is hidden by victim | YouTube ($XXXX) |
IDOR
Logic flaw |
Google |
R ando (@Rando02355205) |
Bug Bounty | 2021-04-20 | 2023-06-13 |
2618 | New Clubhouse Security Vulnerabilities Could Happen to Any Growing Unicorn |
Logic flaw |
Clubhouse |
Katie Moussouris (@k8em0) |
Bug Bounty | 2021-04-21 | 2023-06-13 |