782 | Contrast discovers zero-day flaw in popular Quarkus Java framework |
Drive-by attack
CSRF
RCE |
Quarkus |
Joseph Beeton |
Bug Bounty | 2022-11-23 | 2023-06-13 |
778 | Able to Mass-change profile section leads to my first $BOUNTY$ |
HTML injection
IDOR
CSRF |
NA |
SYRINE |
Bug Bounty | 2022-11-25 | 2023-06-13 |
774 | Exploiting CORS Misconfigurations |
CORS misconfiguration
CSRF
XST |
Apple
Google
Mozilla (Firefox)
WHATWG |
scarlet / attack ships on fire |
Bug Bounty | 2022-11-26 | 2023-06-13 |
613 | Advanced CSRF Exploitation |
CSRF
Stored XSS |
NA |
Sandro Einfeldt |
Bug Bounty | 2023-01-07 | 2023-06-13 |
604 | “2022: A Year of Fascinating Discoveries” |
CSRF
SSRF
Blind XSS
Password reset
Hyperlink injection
IDOR
Weak credentials
AWS misconfiguration |
NA |
dhakal_bibek (@dhakal__bibek) |
Bug Bounty | 2023-01-09 | 2023-06-13 |
598 | Client-Side SSRF to Google Cloud Project Takeover [Google VRP] |
SSRF
CSRF
Open redirect |
Google |
Dohyun Lee |
Bug Bounty | 2023-01-12 | 2023-06-13 |
569 | EmojiDeploy: Smile! Your Azure web service just got RCE’d ._. |
RCE
Cloud
CSRF
CORS misconfiguration |
Microsoft (Azure) |
Liv Matan (@terminatorLM) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
561 | CSRF + Stored XSS Leading to Full Account Takeover |
Stored XSS
CSRF
Account takeover |
NA |
Fares Walid (@SirBagoza) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
497 | SSO Gadgets: Escalate (Self-)XSS to ATO |
SSO
OAuth
Account takeover
Self-XSS
Login CSRF |
NA |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2023-02-04 | 2023-06-13 |
480 | Chaining Bugs to get my First Bug Bounty |
CSRF
Open redirect
Clickjacking
Account takeover |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
457 | Bypassing SameSite=lax cookie restrictions to preform CSRF resulting to a horizontal privilege escalation via poor email verification mechanism |
CSRF |
NA |
Imad Husanovic (@deadoverflow_) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
243 | Unveiling the Secrets: My Journey of Hacking Google’s OSS |
CSRF
Self-XSS |
Google |
7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) |
Bug Bounty | 2023-03-31 | 2023-06-13 |
235 | Simple Bugs 0x01: Password Changing to Account Takeover! |
Account takeover
CSRF |
NA |
Vitor Falcao (@egl_falcao) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
122 | A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF… |
postMessage
JSONP
DOM XSS
CORS misconfiguration
CSRF
WAF bypass |
NA |
Julien Cretel (@jub0bs) |
Bug Bounty | 2023-05-05 | 2023-06-13 |