5096 | One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved. |
Stored XSS
Blind XSS
CSRF
Account takeover
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-02-25 | 2023-06-13 |
5095 | Time-based Blind SQLi on news.starbucks.com |
Blind SQL injection |
Starbucks |
toctou |
Bug Bounty | 2017-02-26 | 2023-06-13 |
5094 | Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token |
postMessage
Violation of secure design principles |
Slack |
Frans Rosén (@fransrosen) |
Bug Bounty | 2017-02-28 | 2023-06-13 |
5093 | Ok Google, Give Me All Your Internal DNS Information! |
SSRF |
Google |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2017-03-01 | 2023-06-13 |
5092 | Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities |
XSS
CSP bypass |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-08 | 2023-06-13 |
5091 | Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat |
Open redirect
SSRF
Path traversal |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-09 | 2023-06-13 |
5090 | How I found a $5,000 Google Maps XSS (by fiddling with Protobuf) |
XSS |
Google |
Marin Moulinier |
Bug Bounty | 2017-03-09 | 2023-06-13 |
5089 | Remote Code Execution in AT&T |
RCE
SSTI
Components with known vulnerabilities |
AT&T |
Corben Leo (@hacker_) |
Bug Bounty | 2017-03-10 | 2023-06-13 |
5088 | Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution |
RCE |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-13 | 2023-06-13 |
5087 | Bypassing Safe Links in Exchange Online Advanced Threat Protection |
Open redirect |
Microsoft |
Mikail Tunç (@emtunc) |
Bug Bounty | 2017-03-16 | 2023-06-13 |
5086 | Penetrating PornHub – XSS vulns galore (plus a cool shirt!) |
XSS |
PornHub |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2017-03-16 | 2023-06-13 |
5085 | Near universal XSS in McAfee Web Gateway |
XSS |
McAfee |
Olivier Arteau |
Bug Bounty | 2017-03-17 | 2023-06-13 |
5084 | Critical information disclosure on Wappalyzer.com |
Information disclosure |
Wappalyzer |
Davide Tampellini (@tampe125) |
Bug Bounty | 2017-03-24 | 2023-06-13 |
5083 | Hundreds of hundreds sub-secdomains hack3d! (including Hacker0ne) |
Subdomain takeover |
HackerOne |
Ak1T4 (@akita_zen) |
Bug Bounty | 2017-03-28 | 2023-06-13 |
5082 | Airbnb – Web to App Phone Notification IDOR to view Everyone’s Airbnb Messages |
IDOR |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-31 | 2023-06-13 |
5081 | Inspect Element leads to Stripe Account Lockout Authentication Bypass |
Authentication bypass |
Stripe |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2017-04-03 | 2023-06-13 |
5080 | AWS S3 bucket misconfiguration - Paytm |
AWS misconfiguration |
Paytm |
Tutorgeeks (@tutorgeeks) |
Bug Bounty | 2017-04-18 | 2023-06-13 |
5079 | Tales of SugarCRM Security Horrors |
PHP Object Injection
SQL injection
Authentication bypass |
SugarCRM |
Egidio Romano / EgiX |
Bug Bounty | 2017-04-23 | 2023-06-13 |
5078 | I got emails — G Suite Vulnerability |
Logic flaw |
Google
Yelp
Meta / Facebook |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-05-05 | 2023-06-13 |
5075 | Hacking the NHS for Fun and No Profit |
SQL injection
LFI |
NHS |
Nathan (@NathOnSecurity) |
Bug Bounty | 2017-05-22 | 2023-06-13 |
5074 | A pair of Plotly bugs: Stored XSS and AWS Metadata SSRF |
Stored XSS
SSRF |
Plotly |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-05-25 | 2023-06-13 |
5073 | Pivoting from blind SSRF to RCE with HashiCorp Consul |
Blind XSS
RCE |
NA |
Peter Adkins (@darkarnium) |
Bug Bounty | 2017-05-29 | 2023-06-13 |
5072 | XSS on Google{5.000$}-Google Vulnerability Reward Program (VRP) |
Stored XSS |
Google |
- |
Bug Bounty | 2017-05-30 | 2023-06-13 |
5071 | Android Browser All Versions - Address Bar Spoofing Vulnerability - CVE-2015-3830 |
Address Bar Spoofing |
Google |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5070 | Nokia Asha Series Lock Screen Bypass |
Authentication bypass
Lock screen bypass |
Nokia |
Hammad Shamsi (@HammadShamsii) |
Bug Bounty | 2017-06-01 | 2023-06-13 |