3262 | Using XAMPP and Burp Intruder when scanning for subdomains to look for interesting behaviour & code |
Information disclosure |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-07-30 | 2023-06-13 |
3239 | The feature works as intended, but what’s in the source? |
Information disclosure |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-08-08 | 2023-06-13 |
3235 | Hacking Zoom: Uncovering Tales of Security Vulnerabilities in Zoom |
Information disclosure
RCE
Memory leak |
Zoom |
Mazin Ahmed (@mazen160) |
Bug Bounty | 2020-08-08 | 2023-06-13 |
3233 | My 2nd 4digit Bug Bounty From Facebook |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2020-08-10 | 2023-06-13 |
3229 | How I was able to find page/personal account disclosure on Instagram |
Information disclosure |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-08-11 | 2023-06-13 |
3222 | Leaking AWS Metadata - The Unusual Way |
Information disclosure
RCE |
NA |
Shubham Garg (@nullb0t) |
Bug Bounty | 2020-08-13 | 2023-06-13 |
3208 | Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties |
Hardcoded API keys
Information disclosure |
Google |
Abss (@absshax) |
Bug Bounty | 2020-08-17 | 2023-06-13 |
3202 | Escalating a GitHub leak to takeover entire organization |
Information disclosure |
NA |
Shashank (@cyberboyIndia) |
Bug Bounty | 2020-08-18 | 2023-06-13 |
3201 | Django debug mode to RCE in Microsoft acquisition |
Information disclosure
RCE |
Microsoft |
Syed Abuthahir (@writerabu) |
Bug Bounty | 2020-08-19 | 2023-06-13 |
3191 | Waze: How I Tracked Your Mother |
Logic flaw
Information disclosure |
Google (Waze) |
Peter Gasper (@malgregator) |
Bug Bounty | 2020-08-25 | 2023-06-13 |
3167 | How often do we overlook vulnerabilities? |
Information disclosure |
HackerOne |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2020-09-09 | 2023-06-13 |
3139 | #Bugbounty- “How I was able to see other users Payments in a travel application” — IDOR #800$ |
IDOR
Information disclosure |
NA |
ganiganesh (@ganiganeshss79) |
Bug Bounty | 2020-09-22 | 2023-06-13 |
3136 | PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover |
IDOR
Information disclosure |
NA |
Pradeep Kumar (@Killer007p) |
Bug Bounty | 2020-09-25 | 2023-06-13 |
3135 | Advisory: security issues in AWS KMS and AWS Encryption SDKs |
Cryptographic issues
Information disclosure |
AWS |
Thai Duong (@XorNinja) |
Bug Bounty | 2020-09-25 | 2023-06-13 |
3130 | P1: Critical - Discovering and Foiling a Threat Actor |
Information disclosure |
NA |
Jackson Henry (@JacksonHHax) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3128 | Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts |
GCP bucket misconfiguration
Information disclosure
Cloud |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3125 | Story of a weird vulnerability I found on Facebook |
Authentication bypass
Information disclosure |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2020-09-30 | 2023-06-13 |
3119 | Spend more time doing recon, you’ll find more BUGS. |
Reflected XSS
Information disclosure |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-10-03 | 2023-06-13 |
3117 | Easy wins : verbose error worth Facebook HOF |
Information disclosure |
Meta / Facebook |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3115 | 90 days, 16 bugs, and an Azure Sphere Challenge |
Local privilege escalation
RCE
DoS
Information disclosure |
Microsoft |
Cisco Talos |
Bug Bounty | 2020-10-06 | 2023-06-13 |
3113 | Sensitive Info Leak in Curve App [Bug Bounty] |
Information disclosure |
Curve |
ΡRΛSΞUDΟ ® (@praseudo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3103 | JS is l0ve ❤️. |
Information disclosure
API key leakage |
NA |
Shivam Kamboj Dattana (@sechunt3r) |
Bug Bounty | 2020-10-09 | 2023-06-13 |
3099 | Disclose Emails, phone numbers, more For Facebook users who tried to add funds to their account |
Information disclosure |
Meta / Facebook |
Mustafa Ahmed (@mustafa0x2021) |
Bug Bounty | 2020-10-12 | 2023-06-13 |
3088 | Back to 2019: Disclosure Employers PII and Credentials |
Information disclosure |
NA |
Wh11teW0lf (@wh11tew0lf) |
Bug Bounty | 2020-10-20 | 2023-06-13 |
3078 | Link Previews: How a Simple Feature Can Have Privacy and Security Risks |
Information disclosure |
Discord
Meta / Facebook
Google
LINE
LinkedIn
Slack
Twitter
Zoom |
Talal Haj Bakry (@parasarora06) |
Bug Bounty | 2020-10-25 | 2023-06-13 |