2613 | Page Owners Can’t remove or change page roles of deactivated users (or if Attacker blocks the page owner) in Facebook Lite, Facebook for Android and touch.facebook.com |
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2608 | Supply Chain Attacks via GitHub.com Releases |
Logic flaw |
GitHub |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2600 | How did I earn €€€€ by breaking the back-end logic of the server |
Logic flaw
Information disclosure |
NA |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2021-04-28 | 2023-06-13 |
2571 | Workplace by Facebook | Unauthorized access to companies environment — $27,5k |
Authorization flaw
Logic flaw
IDOR |
Meta / Facebook |
Marcos Ferreira (@mvinni_) |
Bug Bounty | 2021-05-07 | 2023-06-13 |
2567 | Simple logical Bug turned into a bounty |
Logic flaw |
Meta / Facebook |
Sndp Giri |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2555 | How to prevent more than 200 million users from using Google services |
Logic flaw |
Google |
Omar Hashem (@OmarHashem666) |
Bug Bounty | 2021-05-16 | 2023-06-13 |
2541 | Writeups: Facebook Whitehat program(2021): Instagram Live setting bug |
Logic flaw |
Meta / Facebook |
Takashi Suzuki |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2540 | Third-Party Apps were still getting your private Facebook data even after their access expiry. |
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2499 | Shopify Multipass Misconfiguration |
Authentication flaw
Logic flaw |
NA |
Ahmed A. Sherif |
Bug Bounty | 2021-06-05 | 2023-06-13 |
2497 | How I could have accessed all your private videos/photos saved inside your device without even unlocking it? |
Authorization flaw
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-06-06 | 2023-06-13 |
2493 | Author spoofing in Google Colaboratory |
Logic flaw |
Google |
Zohar Shachar |
Bug Bounty | 2021-06-09 | 2023-06-13 |
2487 | How I found the silliest logical vulnerability for $750 that no one found for 3 years |
Logic flaw |
NA |
Sina Kheirkhah (@SinSinology) |
Bug Bounty | 2021-06-12 | 2023-06-13 |
2485 | [Google VRP] Privilege escalation on https://dialogflow.cloud.google.com |
Authorization flaw
Logic flaw |
Google |
lalka (@0x01alka) |
Bug Bounty | 2021-06-13 | 2023-06-13 |
2475 | One-click DOS via Response Manipulation |
Logic flaw |
NA |
Akhil |
Bug Bounty | 2021-06-16 | 2023-06-13 |
2473 | Part-1 Dive into Zoom Applications |
CSRF
Payment bypass
Logic flaw
Account takeover
Privilege escalation |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-06-16 | 2023-06-13 |
2455 | Three Microsoft Store vulnerabilites |
Payment tampering
Logic flaw |
Microsoft |
Marlon Fabiano (@astrounder) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2454 | Microsoft Store free purschase vulnerabilites |
Payment tampering
Logic flaw |
Microsoft |
Marlon Fabiano (@astrounder) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2428 | Let’s cancel the subscription (informative) |
Logic flaw
Payment tampering |
NA |
Adnan Malik (@adnanmalikinfo) |
Bug Bounty | 2021-07-07 | 2023-06-13 |
2415 | Part 2: Dive into Zoom Applications |
CSRF
Account takeover
Information disclosure
Session expiration issue
Authorization flaw
Logic flaw |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2390 | Story OF MY 3RD Bounty From Facebook |
Logic flaw |
NA |
Aashish Jung Kunwar (@WhoisAasis) |
Bug Bounty | 2021-07-23 | 2023-06-13 |
2346 | Account Takeover (User + Admin) Via Password Reset |
Account takeover
Password reset
Logic flaw |
NA |
Hemant Patidar (@HemantSolo) |
Bug Bounty | 2021-08-05 | 2023-06-13 |
2333 | How I Bought a £240.00 Annual Subscription for Bargain £0.01 |
Payment tampering
Logic flaw |
NA |
Craig Hays (@craighays) |
Bug Bounty | 2021-08-11 | 2023-06-13 |
2327 | Facebook Bug:Invite user to Like a Page even after they decline the Page Like Invite |
Logic flaw |
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2312 | Disclose WhatsApp Number of Instagram Accounts Despite Setting Set to be Hidden |
Information disclosure
Logic flaw |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2303 | Hey Google ! - Delete my Data Properly — #GoogleVRP |
Logic flaw |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2021-08-23 | 2023-06-13 |