2750 | Join Facebook Group With Unpublish Page |
Authorization flaw |
Meta / Facebook |
gevakun |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2749 | Secret Key Exposure in API Config Directory |
Information disclosure |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2748 | Exploiting CORS to perform an IDOR Attack leading to PII Information Disclosure |
CORS misconfiguration
Information disclosure |
NA |
Harsh Parekh (@notmarshmllow) |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2747 | GKE Autopilot Node Compromise via local-storage PersistentVolume |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2746 | Microsoft Edge Browser For IOS - Address Bar Spoofing Vulnerability |
Address Bar Spoofing |
Microsoft |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2021-03-02 | 2023-06-13 |
2745 | How I Might Have Hacked Any Microsoft Account |
Account takeover
Password reset
Bruteforce
MFA bypass |
Microsoft |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-03-02 | 2023-06-13 |
2744 | The Invincible Kid |
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2743 | Content Injection (RCE) in Yandex Browser for Android [2018] |
MiTM |
Yandex |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2742 | Stored XSS at Trello.com |
Stored XSS |
Trello |
Maor Dayan (@mord1234) |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2741 | Low hanging fruits on Facebook Group Room. Unable to remove post on group when post room add with event ($500) |
Logic flaw |
Meta / Facebook |
Randy Arios |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2740 | Leveraging Template injection to takeover an account. |
CSTI
XSS |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2739 | GKE Autopilot Node Compromise via startup-script |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-03-05 | 2023-06-13 |
2738 | GKE Autopilot Node Compromise via SSH Metadata |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-03-05 | 2023-06-13 |
2737 | The easiest $2500 I got it from bug bounty program |
Information disclosure |
Uber |
Abdullah Mohamed (@3bodymo_) |
Bug Bounty | 2021-03-06 | 2023-06-13 |
2736 | Exploiting a hidden and forgotten Bug |
SSRF |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2735 | Finding Hidden Login Endpoint Exposing Secret `Client ID` |
Information disclosure |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2734 | Stored XSS in Google Ads Android Application— $3133.70 |
Stored XSS
HTML injection |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2733 | Partially disable Cybereason EDR as low privileges user on Windows |
EDR bypass
Local Privilege Escalation |
Cybereason |
Mehdi Alouache |
Bug Bounty | 2022-10-28 | 2023-06-13 |
2732 | Bypassing Chrome%27s URL restrictions |
Browser hacking
URL validation bypass |
Google (Chrome) |
Jeffrey Bencteux (@jeffbencteux) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2731 | Dangling DNS: Amazon EC2 IPs (Current State) |
Dangling DNS records
Subdomain takeover |
8x8 |
Mohamed Elbadry (@_melbadry9) |
Bug Bounty | 2021-03-08 | 2023-06-13 |
2730 | Write Up – Google VRP N/A: SSRF Bypass With Quadzero In Google Cloud Monitoring |
SSRF |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-03-08 | 2023-06-13 |
2729 | Exploiting HTTP Request Smuggling (TE.CL)— XSS to website takeover |
HTTP request smuggling
XSS |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2021-03-09 | 2023-06-13 |
2728 | Dangling DNS Records on surf-test.xwf.internet.org (Amazon EC2)! |
Subdomain takeover
Dangling DNS records |
Meta / Facebook |
Binit Ghimire (@WHOISbinit) |
Bug Bounty | 2021-03-10 | 2023-06-13 |
2727 | Finding Basic Authtoken in JAVASCRIPT file BY Full Automation |
Information disclosure |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-03-10 | 2023-06-13 |
2726 | Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover |
Reflected XSS
Clickjacking
Account takeover |
NA |
pleorqy (@pleorqy) |
Bug Bounty | 2021-03-10 | 2023-06-13 |