3051 | Attack of the clones: Git clients remote code execution |
RCE |
GitHub |
Vitor Fernandes (@Rapt00rVF) |
Bug Bounty | 2020-11-06 | 2023-06-13 |
3049 | How i could take over any Account on a USA Department of Defense Website due to a simple IDOR |
IDOR
Account takeover |
U.S. Dept Of Defense |
Gal Nagli (@naglinagli) |
Bug Bounty | 2020-11-07 | 2023-06-13 |
3048 | Silver Peak Unity Orchestrator RCE |
RCE
Authentication bypass
Path traversal
SQL injection |
Silver Peak |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-08 | 2023-06-13 |
3046 | Firefox for Android: LAN-Based Intent Triggering |
Insecure intent
Android |
Mozilla |
initstring (@init_string) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3045 | Chaining password reset link poisoning, IDOR, and information leakage to achieve account takeover at api.redacted.com |
HTTP header injection |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3044 | SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever ! |
SSRF |
Dropbox |
Sayaan Alam (@ehsayaan) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3043 | 31k$ SSRF in Google Cloud Monitoring led to metadata exposure |
SSRF |
Google |
David Nechuta (@david_nechuta) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3042 | id.atlassian.com Username enumeration |
Username enumeration |
Atlassian |
Denis Andzakovic |
Bug Bounty | 2020-11-11 | 2023-06-13 |
3041 | Local Privilege Escalation Vulnerability Discovered in VMware Fusion |
Local Privilege Escalation |
VMware |
Rich Mirch (@0xm1rch) |
Bug Bounty | 2020-11-11 | 2023-06-13 |
3040 | Evernote: Universal-XSS, theft of all cookies from all sites, and more |
Universal XSS |
Evernote |
Oversecured (@OversecuredInc) |
Bug Bounty | 2020-11-12 | 2023-06-13 |
3039 | Evading Filters to perform the Arbitrary URL Redirection Attack |
Open redirect |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-11-12 | 2023-06-13 |
3038 | User’s private watched videos/saved videos exposed through a messenger call from a locked smartphone. |
Information disclosure
Authorization flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3037 | How a simple bug in Facebook Lite let me win my first bug bounty from Facebook |
Information disclosure |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3036 | Interesting case of SQLi |
SQL injection |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3035 | How I Found The Facebook Messenger Leaking Access Token Of Million Users |
Information disclosure |
Meta / Facebook |
Guhan Raja (@havocgwen) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3034 | Smuggling an (Un)exploitable XSS |
HTTP Request Smuggling
XSS |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3033 | Replying Comments On Someone’s LiveStream From Page is Posted as Personal Identity |
Logic flaw |
Meta / Facebook |
Prakash Panta (@Prakashpanta268) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3032 | Theoretically Possible To Practical Account Takeover |
IDOR
Account takeover |
NA |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2020-11-14 | 2023-06-13 |
3031 | Account takeover through password reset |
Account takeover
Password reset |
NA |
Omar Hamdy (@seaman00o) |
Bug Bounty | 2020-11-14 | 2023-06-13 |
3030 | SD-PWN Part 2 — Citrix SD-WAN Center — Another Network Takeover |
RCE
Authentication bypass
Path traversal
OS command injection
Local Privilege Escalation |
Citrix Systems |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3029 | Exploiting API with AuthToken |
Token leak
Information disclosure |
NA |
Rafi Ahamed (Leonidas D. Ace) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3028 | Weak Cryptography to Account Takeover’s |
Cryptographic issues
Account takeover
IDOR |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3027 | Microsoft Bug Bounty Writeup – Stored XSS Vulnerability |
Stored XSS |
Microsoft |
Pethuraj (@Pethuraj) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3026 | Optimizing Hunting Results in VDP for use in Bug Bounty Programs - From Sensitive Information Disclosure to Accessing Hidden APIs which can be used to Retrieve Customer Data |
Information disclosure
Broken access control
IDOR
SQL injection |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3025 | RCE via Server-Side Template Injection |
SSTI
RCE |
NA |
Gaurav Mishra (@gmishra010) |
Bug Bounty | 2020-11-15 | 2023-06-13 |