3130 | P1: Critical - Discovering and Foiling a Threat Actor |
Information disclosure |
NA |
Jackson Henry (@JacksonHHax) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3129 | Taking down the SSO, Account Takeover in the Websites of Kolesa due to Insecure JSONP Call |
Account takeover |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2020-09-28 | 2023-06-13 |
3128 | Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts |
GCP bucket misconfiguration
Information disclosure
Cloud |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3127 | The Art of IDOR: 7 IDORs in Edm0d0 |
IDOR |
Edmodo |
Pratyush Anjan Sarangi |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3126 | RCE on Spip and Root-Me |
RCE
SQL injection
XSS
Open redirect
Reflected file download |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3125 | Story of a weird vulnerability I found on Facebook |
Authentication bypass
Information disclosure |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2020-09-30 | 2023-06-13 |
3124 | Write Up – Google Bug Bounty: XSS To Cloud Shell Instance Takeover (Rce As Root) – $5,000 USD |
XSS
RCE |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2020-10-01 | 2023-06-13 |
3123 | The Powerful HTTP Request Smuggling 💪 |
HTTP Request Smuggling |
NA |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2020-10-01 | 2023-06-13 |
3122 | Arbitrary code execution on Facebook for Android through download feature |
Arbitrary code execution |
Meta / Facebook |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2020-10-02 | 2023-06-13 |
3121 | Journey Of My First Bug Bounty (Nov 2018) |
Authentication bypass |
Samsung |
Harsh Tyagi (@harshtya9i) |
Bug Bounty | 2020-10-02 | 2023-06-13 |
3120 | Exploiting Payment Gateways |
Payment tampering |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-10-03 | 2023-06-13 |
3119 | Spend more time doing recon, you’ll find more BUGS. |
Reflected XSS
Information disclosure |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-10-03 | 2023-06-13 |
3118 | Leveraging LFI to RCE in a website with +20000 users |
LFI
RCE |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2020-10-04 | 2023-06-13 |
3117 | Easy wins : verbose error worth Facebook HOF |
Information disclosure |
Meta / Facebook |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3116 | Watch your requests! Open redirect to a complete account takeover |
Path traversal
Open redirect
SSRF
Account takeover |
NA |
Suraj Disoja (@ninetyn1ne_) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3115 | 90 days, 16 bugs, and an Azure Sphere Challenge |
Local privilege escalation
RCE
DoS
Information disclosure |
Microsoft |
Cisco Talos |
Bug Bounty | 2020-10-06 | 2023-06-13 |
3114 | Our Experiences Participating in Microsoft’s Azure Sphere Bounty Program |
Local privilege escalation
RCE
Security Feature bypass |
Microsoft |
McAfee Advanced Threat Research (ATR) |
Bug Bounty | 2020-10-06 | 2023-06-13 |
3113 | Sensitive Info Leak in Curve App [Bug Bounty] |
Information disclosure |
Curve |
ΡRΛSΞUDΟ ® (@praseudo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3112 | 6k$ Worth Account Takeover via IDOR in Starbucks Singapore |
IDOR
Account takeover |
Starbucks |
Kamil Onur Özkaleli (@ko2sec) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3111 | Research: The mass CSRFing of *.google.com/* products. |
CSRF |
Google |
Missoum Said (@missoum1307) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3108 | Kud I Enter Your Server? New Vulnerabilities in Microsoft Azure |
Privilege escalation
RCE
Cloud |
Microsoft |
Intezer |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3107 | ATO via Host Header Poisoning |
Host header injection
Account takeover
Password reset |
NA |
Shivam Kamboj Dattana (@sechunt3r) |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3106 | Exploiting Admin Panel Like a Boss |
Authorization bypass
Weak credentials |
NA |
Shivam Kamboj Dattana (@sechunt3r) |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3105 | CVE-2018–5230 | JIRA Cross Site Scripting |
Reflected XSS |
NA |
Paras Arora (@parasarora06) |
Bug Bounty | 2020-10-09 | 2023-06-13 |