2818 | Hacking Chess.com and Accessing 50 Million Customer Records |
Reflected XSS
Information disclosure
Account takeover |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2814 | OAuth Misconfiguration Leads to Full Account takeover |
OAuth
Clickjacking
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-02-13 | 2023-06-13 |
2802 | Full account takeover worth $1000 Think out of the box |
Account takeover
CSRF
IDOR |
NA |
Mohsin Khan (@tabaahi_) |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2794 | Story of a very lethal IDOR. |
XSS
IDOR
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2021-02-17 | 2023-06-13 |
2782 | Account Take Over by Response Manipulation |
Authentication bypass
Account takeover |
NA |
Naveen J (@thevillagehackr) |
Bug Bounty | 2021-02-17 | 2023-06-13 |
2779 | Account Takeover via Response Manipulation worth 1800$.. |
Authentication bypass
OTP bypass
Account takeover |
NA |
Ashutosh mishra (@ashutoshmish_ra) |
Bug Bounty | 2021-02-20 | 2023-06-13 |
2775 | Web Cache Poisoning to Account Takeover |
Web cache poisoning
Account takeover |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-21 | 2023-06-13 |
2770 | Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up) |
Host header injection
Account takeover
Password reset |
Niteflirt |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2767 | Password Reset Token Leak via X-Forwarded-Host |
Host header injection
Account takeover
Password reset |
NA |
Saajan Bhujel (@saajanbhujel) |
Bug Bounty | 2021-02-26 | 2023-06-13 |
2766 | Account Takeover - Smoking with null’ |
Account takeover
Authentication flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-02-26 | 2023-06-13 |
2758 | Any Account Takeover Through Privilege Escalation |
Privilege escalation
Account takeover |
NA |
Shubham Chaskar (@chaskar_shubham) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2745 | How I Might Have Hacked Any Microsoft Account |
Account takeover
Password reset
Bruteforce
MFA bypass |
Microsoft |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-03-02 | 2023-06-13 |
2726 | Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover |
Reflected XSS
Clickjacking
Account takeover |
NA |
pleorqy (@pleorqy) |
Bug Bounty | 2021-03-10 | 2023-06-13 |
2722 | Account Takeover Via Reset Password Worth 2000$ |
Password reset
Account takeover |
NA |
Ashutosh mishra (@ashutoshmish_ra) |
Bug Bounty | 2021-03-12 | 2023-06-13 |
2714 | An Interesting Account Takeover!! |
IDOR
Account takeover
Weak encryption
Password reset |
NA |
Mayank Pandey (@mayank_pandey01) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2711 | Abusing Data Protection Laws For D0xing & Account Takeovers |
SSTI
Account takeover |
NA |
Hx01 (@Hxzeroone) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2707 | How I hacked Facebook: Part Two |
SSRF
Account takeover
Cookie manipulation |
Meta / Facebook |
Alaa Abdulridha (@alaa0x2) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2689 | Increasing impact of Information Disclosure — Full Account Takeover ! |
Information disclosure
Password reset |
NA |
Abhisek R (@abh1sek_r) |
Bug Bounty | 2021-03-26 | 2023-06-13 |
2684 | CSRF to Full Account Takeover |
CSRF
Account takeover |
NA |
Ashraf Harb (@ashrafharb97) |
Bug Bounty | 2021-03-29 | 2023-06-13 |
2681 | Missing CORS leads to Complete Account Takeover |
Missing CORS
CSRF
Account takeover |
NA |
Niraj Modi (@nirajmodi51) |
Bug Bounty | 2021-03-30 | 2023-06-13 |
2677 | Zero click vulnerability in Apple’s macOS Mail |
Account takeover
Information disclosure
RCE |
Apple |
Mikko Kenttälä (@Turmio_) |
Bug Bounty | 2021-04-01 | 2023-06-13 |
2650 | Unauthenticated Account Takeover Through Forget Password |
Password reset
Account takeover
Information disclosure |
NA |
Nikhil (niks) (@niksthehacker) |
Bug Bounty | 2021-04-12 | 2023-06-13 |
2636 | Lets Learn English - Hacking 10M+ Users |
AWS misconfiguration
Insecure Firebase database
OTP bypass
Account takeover
Logic flaw |
NA |
Aseem Shrey (@AseemShrey) |
Bug Bounty | 2021-04-17 | 2023-06-13 |
2632 | Misconfiguration in Change-password Functionality Leads to Account Takeover |
IDOR
Logic flaw
Password reset
Account takeover |
NA |
Mahmoud Radwan (@0x___2m) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2610 | From Wayback Machine To Account Takeover |
Account takeover
Password reset
Open redirect |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-04-25 | 2023-06-13 |