3355 | Using Inspect Element to Bypass Security restrictions | Bug Bounty POC |
Client-side enforcement of server-side security |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-06-30 | 2023-06-13 |
3351 | ZombieVPN, Breaking That Internet Security |
RCE
Insecure deserialization |
Bitdefender
AnchorFree |
0xSha (@0xsha) |
Bug Bounty | 2020-07-01 | 2023-06-13 |
3340 | Bug bounty write-up: From SSRF to $4000 |
SSRF
RCE |
NA |
thehackerish (@thehackerish) |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3331 | RCE via image upload functionality |
Unrestricted file upload
RCE |
NA |
Adwaith KS |
Bug Bounty | 2020-07-05 | 2023-06-13 |
3323 | How I found 10 Remote Code Execution in 10 minutes CVE-2020–5902 |
RCE |
NA |
Saransh Srivastav (@malfuncti0n_) |
Bug Bounty | 2020-07-07 | 2023-06-13 |
3316 | Tenda AC15 AC1900 Vulnerabilities Discovered and Exploited |
CSRF
XSS
Hardcoded credentials
RCE |
Tenda |
Sanjana Sarda |
Bug Bounty | 2020-07-10 | 2023-06-13 |
3312 | How I hacked into a Telecom Network |
RCE
Security misconfiguration
JBoss |
NA |
Harpreet Singh |
Bug Bounty | 2020-07-11 | 2023-06-13 |
3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3285 | Hunting Android Application Bugs Using Android Studio. |
Authorization flaw
Client-side enforcement of server-side security
Information disclosure |
NA |
Tarek Mohammed (@Conan0x3) |
Bug Bounty | 2020-07-24 | 2023-06-13 |
3280 | How I bypassed 2fa in a 3 years old private program! |
MFA bypass
Bruteforce
Lack of rate limiting |
NA |
Shivangx01b (@shivangx01b) |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3269 | XSS, RCE & HTML File Upload in same endpoint |
XSS
RCE
Unrestricted file upload |
NA |
Tarikul Islam (@sa1tama0) |
Bug Bounty | 2020-07-29 | 2023-06-13 |
3239 | The feature works as intended, but what’s in the source? |
Information disclosure |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-08-08 | 2023-06-13 |
3235 | Hacking Zoom: Uncovering Tales of Security Vulnerabilities in Zoom |
Information disclosure
RCE
Memory leak |
Zoom |
Mazin Ahmed (@mazen160) |
Bug Bounty | 2020-08-08 | 2023-06-13 |
3222 | Leaking AWS Metadata - The Unusual Way |
Information disclosure
RCE |
NA |
Shubham Garg (@nullb0t) |
Bug Bounty | 2020-08-13 | 2023-06-13 |
3218 | Crowdsource Success Story: From an Out-of-Scope Open Redirect to CVE-2020-1323 |
Open redirect |
Microsoft |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-08-14 | 2023-06-13 |
3217 | Open Sesame: Escalating Open Redirect to RCE with Electron Code Review |
Open redirect
RCE
Security code review |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-08-14 | 2023-06-13 |
3204 | How to contact Google SRE: Dropping a shell in cloud SQL |
SQL injection
Privilege escalation
Parameter injection
RCE |
Google |
wtm@offensi.com (@wtm_offensi) |
Bug Bounty | 2020-08-18 | 2023-06-13 |
3201 | Django debug mode to RCE in Microsoft acquisition |
Information disclosure
RCE |
Microsoft |
Syed Abuthahir (@writerabu) |
Bug Bounty | 2020-08-19 | 2023-06-13 |
3188 | Delete IDOR on a Fashion eCommerce Website |
IDOR |
NA |
Amey Anekar (@ameyanekar) |
Bug Bounty | 2020-08-26 | 2023-06-13 |
3183 | Unhiding the hidden |
Client-side enforcement of server-side security
Authorization flaw
CSRF |
NA |
I am Broot |
Bug Bounty | 2020-08-31 | 2023-06-13 |
3175 | How_i_was_able_to_pawned_website_via_escilating_webcache deception to rce |
Web cache deception
SSRF
RCE |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2020-09-05 | 2023-06-13 |
3170 | From Android Static Analysis to RCE on Prod |
RCE
Directory listing
Missing authentication |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2020-09-07 | 2023-06-13 |
3168 | CVE-2020-8150 – Remote Code Execution as SYSTEM/root via Backblaze |
RCE
Local Privilege Escalation |
Backblaze |
Jason Geffner (@JasonGeffner) |
Bug Bounty | 2020-09-09 | 2023-06-13 |
3164 | How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM |
RCE
JNDI Injection |
Meta / Facebook |
Orange Tsai (@orange_8361) |
Bug Bounty | 2020-09-12 | 2023-06-13 |
3162 | SQL Injection & Remote Code Execution - Double P1 |
SQL injection
RCE |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-09-13 | 2023-06-13 |