Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3636Discord embed spoofing Phishing Discord DarkMatterMatt Bug Bounty2020-03-022023-06-13
3277CVE-2020–9934: Bypassing the macOS Transparency, Consent, and Control (TCC) Framework for unauthorized access to sensitive user data MacOS Local Privilege Escalation Authorization flaw Apple Matt Shockley (@mattshockl) Bug Bounty2020-07-272023-06-13
2961Github Secrets exposed due to RCE in Formatter Action from pull_request_target event RCE Google Anthony Weems Bug Bounty2020-12-172023-06-13
2839Microsoft Remote Desktop Web Access Authentication Timing Attack Timing attack Authentication flaw Microsoft Matt Dunn Bug Bounty2021-02-042023-06-13
2720How I Found Sql Injection on 8x8 , Cengage,Comodo,Automattic,20 company SQL injection Automattic IBM 8x8 Ahmad A Abdulla (@lu3ky13) Bug Bounty2021-03-122023-06-13
2577How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350 SQL injection Automattic Ahmad A Abdulla (@lu3ky13) Bug Bounty2021-05-052023-06-13
2383Mattermost Server v5.32 > v5.36 Reflected XSS in OAuth flow Reflected XSS OAuth Mattermost zi0Black (@zi0Black) Bug Bounty2021-07-262023-06-13
2340Size Matters — CVE-2021–0485 (High) Local Privilege Escalation Android Google Dimitrios Valsamaras (@Ch0pin) Bug Bounty2021-08-072023-06-13
1826"Zero-Days" Without Incident - Compromising Angular via Expired npm Publisher Email Domains Supply chain attack GitHub Matthew Bryant (@IAmMandatory) Bug Bounty2022-02-112023-06-13
1810CVE-2022-0478 - WooCommerce Event-Manager Plugin SQL Injection SQL injection Security code review Automattic (WooCommerce) Castilho (@castilho101) Bug Bounty2022-02-162023-06-13
1064Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286) Local Privilege Escalation Windows Driver hacking Seagate x86matthew (@x86matthew) Bug Bounty2022-09-202023-06-13
689FlowscreenComponents Basepack, Version 3.0.7 Advisory XSS Security code review UnofficialSF Matthew Rutledge Bug Bounty2022-12-152023-06-13
647Turning Google smart speakers into wiretaps for $100k IoT Wifi hacking Google Matt Bug Bounty2022-12-262023-06-13
575Sudoedit bypass in Sudo <= 1.9.12p1 (CVE-2023-22809) Local Privilege Escalation Sudo Matthieu Barjole (@aevy__) Bug Bounty2023-01-182023-06-13
325Wait Time Bypass for fun and Profit Rate limiting bypass Automattic the_unluck_guy (@7he_unlucky_guy) Bug Bounty2023-03-102023-06-13
116Size matters! When capital letters introduce vulnerabilities XSS Microsoft Mario Stathakopoulos Bug Bounty2023-05-062023-06-13
110A deep-dive on Pluck CMS vulnerability CVE-2023-25828 Unrestricted file upload RCE Security code review Pluck CMS Matthew Hogg Bug Bounty2023-05-082023-06-13