2921 | Subdomain Take Over Worth 100£ |
Subdomain takeover |
NA |
c0d3x27 (@c0d3x27) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2920 | Stored XSS on Product Description [HIGH] — $400 |
Stored XSS |
NA |
Emanuel Beni Harijanto |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2919 | Github Organization Takeover By Claiming Owner Invitation |
Account takeover
Logic flaw |
GitHub |
Abss (@absshax) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2918 | $10,000 for a vulnerability that doesn’t exist |
Path traversal |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2916 | Information Disclosure through Signup Endpoint |
Information disclosure |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2915 | Blind XSS in Google Analytics Admin Panel — $3133.70 |
Blind XSS |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2914 | Exploiting Application-Level Profile Semantics (APLS) |
APLS misconfiguration
API misconfiguration |
NA |
Niemand (@niemand_sec) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2913 | Create post on any Facebook page |
IDOR |
Meta / Facebook |
Pouya Darabi (@Pouyadarabi) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2912 | A %27Novel%27 Way to Bypass Executable Signature Checks with Electron |
Local Privilege Escalation |
NA |
Parsia Hackerman (@cryptogangsta) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2911 | How I was able to Regain access to account deleted by Admin leading to $$$ |
Logic flaw
Authorization flaw |
NA |
Rajesh Ranjan (@_rajesh_ranjan_) |
Bug Bounty | 2021-01-10 | 2023-06-13 |
2910 | Unauthorized Access to OData Entities + $2K Bounty From Microsoft |
Authorization flaw
Information disclosure |
Microsoft |
Borna Nematzadeh (@LogicalHunter) |
Bug Bounty | 2021-01-10 | 2023-06-13 |
2909 | Weblogic Remote Code Execution (Exploiting CVE-2019-2725) |
RCE |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2021-01-10 | 2023-06-13 |
2908 | UNEP Breached, 100K+ Employee Records Accessed |
Information disclosure |
United Nations |
Jackson Henry (@JacksonHHax) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2907 | Stealing Your Private YouTube Videos, One Frame at a Time |
IDOR |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2906 | Guest Blog Post: Leaking silhouettes of cross-origin images |
Side-channel information leakage
Browser hacking |
Mozilla
Google (Chrome) |
Aleksejs Popovs (@aleksejspopovs) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2905 | Unrestricted File Upload |
Unrestricted file upload |
NA |
Binamra Pandey |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2904 | CSRF with IDOR - A Deadly Combo |
CSRF
IDOR |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2903 | Stealing User Information Via XSS Via Parameter Pollution |
Open redirect
XSS |
NA |
Hamza Avvan (@hamzaavvan) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2902 | Making Clouds Rain :: Remote Code Execution in Microsoft Office 365 |
RCE |
Microsoft |
Steven Seeley (@steventseeley) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2901 | GoCD Multiple Vulnerabilities |
RCE
Information disclosure
Insecure deserialization
Security code review |
GoCD |
Denis Andzakovic |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2900 | Story of a really cool SSRF bug. |
SSRF |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2021-01-13 | 2023-06-13 |
2899 | How I managed to trigger a Stored-XSS in an online store with the help of Cache Poisoning |
Web cache poisoning
Stored XSS |
NA |
Schizo! |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2898 | Tale of 2 TOOTB Bugs: Google and WhatsApp |
Information disclosure
Logic flaw |
Google
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2897 | Irremovable Facebook group album photos and entire album under certain circumstances (Bounty: 1000 USD) |
Logic flaw |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2896 | Insertion Of Malicious Links For Execution In Profile Picture - Unvalidated User Input In MS Sharepoint 2019 (CVE-2020-1456) |
XSS |
Microsoft |
David (@slashcrypto) |
Bug Bounty | 2021-01-15 | 2023-06-13 |