3617 | Finding a P1 in one minute with Shodan.io (RCE) |
RCE |
NA |
sw33tLie (@sw33tLie) |
Bug Bounty | 2020-03-11 | 2023-06-13 |
3610 | How I got access to critical data of a Company in no time ? |
Information disclosure
Lack of rate limiting
Bruteforce |
NA |
Kaustubh Kale |
Bug Bounty | 2020-03-12 | 2023-06-13 |
3591 | Remote Image Upload Leads to RCE (Inject Malicious Code to PHP-GD Image) |
Unrestricted file upload
RCE |
NA |
Muhammad R. Maulana |
Bug Bounty | 2020-03-21 | 2023-06-13 |
3578 | Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study |
RCE |
Bitdefender |
Abdulrahman Nour (@aboodnour) |
Bug Bounty | 2020-03-28 | 2023-06-13 |
3577 | OTP Bruteforce- Account Takeover |
OTP bruteforce
Account takeover |
NA |
Ranjit Kumar |
Bug Bounty | 2020-03-29 | 2023-06-13 |
3571 | Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC |
RCE |
Microsoft |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-03-31 | 2023-06-13 |
3551 | Hacking a Telecommunication company(MTN) |
OTP bypass
Bruteforce |
MTN Group |
Afolic |
Bug Bounty | 2020-04-13 | 2023-06-13 |
3540 | CSRF to RCE bug chain in Prestashop v1.7.6.4 and below |
RCE
CSRF
Stored XSS
Unrestricted file upload |
PrestaShop |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-04-18 | 2023-06-13 |
3532 | Misconfigured WordPress takeover to Remote Code Execution |
Wordpress takeover
RCE
Security misconfiguration |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3524 | 1-click RCE on Keybase |
RCE |
Keybase |
smaury (@smaury92) |
Bug Bounty | 2020-04-27 | 2023-06-13 |
3472 | My first 10k bdt bounty from an e-commerce site |
IDOR |
NA |
Md Saikat |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3462 | RCE in Google Cloud Deployment Manager |
SSRF
RCE |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3459 | How Source code reading helped me find an IDOR |
IDOR
Information disclosure |
NA |
Sanjay Verdu (@codersanjay) |
Bug Bounty | 2020-05-22 | 2023-06-13 |
3457 | How dangerous is Request Splitting, a vulnerability in Golang or how we found the RCE in Portainer and hacked Uber |
HTTP request splitting
SSRF
CRLF injection
RCE |
Uber |
Andrey Abakumov (@andrewaeva) |
Bug Bounty | 2020-05-25 | 2023-06-13 |
3435 | Hunting on ASPX Application For P1%27s [Unauthenticated SOAP,RCE, Info Disclosure] |
RCE
Information disclosure
IDOR |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-05-31 | 2023-06-13 |
3410 | The Accidental RCE |
Unrestricted file upload |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-06-09 | 2023-06-13 |
3404 | Guest Blog: From File Upload to RCE |
Unrestricted file upload
RCE |
NA |
Lukasz Wierzbicki (@v13rs8a) |
Bug Bounty | 2020-06-10 | 2023-06-13 |
3398 | Account Takeover via OTP Bruteforce (Apigee API) |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2020-06-13 | 2023-06-13 |
3385 | How I managed to Escalate privilege as admin |
Lack of rate limiting
Bruteforce
Weak credentials |
NA |
Abisheik Magesh (@AbisheikMagesh) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3384 | How I made more than $30K with Jolokia CVEs |
Reflected XSS
RCE
Information disclosure |
NA |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3382 | A subtle stored-XSS in WordPress core |
Stored XSS
RCE |
WordPress |
Sam Thomas (@_s_n_t) |
Bug Bounty | 2020-06-17 | 2023-06-13 |
3375 | Bypass 2FA like a Boss |
Lack of rate limiting
Bruteforce |
NA |
Seqrity (@seQrity) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3373 | It took me only 5 minutes to find an RCE on Bentley |
RCE
Weak credentials |
Bentley |
Divyansh Sharma |
Bug Bounty | 2020-06-21 | 2023-06-13 |
3368 | Exploiting Bitdefender Antivirus: RCE from any website |
RCE
Information disclosure |
Bitdefender |
Wladimir Palant (@WPalant) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3362 | Bypassing file upload filter by source code review in Bolt CMS |
RCE
Unrestricted file upload
Path traversal
Security code review |
Bolt CMS |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-06-27 | 2023-06-13 |