4740 | Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected) |
SOP bypass
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4709 | Take Advantage of Out-of-Scope Domains in Bug Bounty Programs |
XSS |
NA |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2018-06-27 | 2023-06-13 |
4704 | The $12,000 Intersection between Clickjacking, XSS, and Denial of Service |
Clickjacking
XSS
DoS |
Bustabit |
Sam Curry (@samwcyo) |
Bug Bounty | 2018-07-04 | 2023-06-13 |
4687 | Oracle WebLogic - Multiple SAML Vulnerabilities (CVE-2018-2998/CVE-2018-2933) |
SAML
Authentication bypass |
Oracle (WebLogic) |
Denis Andzakovic |
Bug Bounty | 2018-07-18 | 2023-06-13 |
4562 | Just another tale of severe bugs on a private program. |
Open redirect
SSRF
IDOR
Logic flaw |
NA |
Siva Krishna Samireddi (@le4rner) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4555 | Applying a small bypass to steal Facebook Session tokens in Uber |
XSS
CSP bypass
OAuth |
Uber |
Samuel (@saamux) |
Bug Bounty | 2018-10-02 | 2023-06-13 |
4519 | Google sites and exploiting same origin policy |
SOP bypass |
Google |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2018-10-22 | 2023-06-13 |
4465 | Edmodo XSS Bug |
XSS |
Edmodo |
Sameer Phad (@sameerphad72) |
Bug Bounty | 2018-11-18 | 2023-06-13 |
4426 | My first bug bounty writeup |
XSS
HTML injection |
Indeed |
Sampanna Chimoriya |
Bug Bounty | 2018-12-10 | 2023-06-13 |
4424 | How I was able to generate Access Tokens for any Facebook user. |
IDOR
Information disclosure |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2018-12-11 | 2023-06-13 |
4407 | Reading ASP secrets for $17,000 |
Local file disclosure (LFD) |
NA |
Sam Curry (@samwcyo) |
Bug Bounty | 2018-12-16 | 2023-06-13 |
4393 | RCE in nokia.com |
RCE |
Nokia |
Sampanna Chimoriya |
Bug Bounty | 2018-12-27 | 2023-06-13 |
4268 | Fixed : Brute-force Instagram account’s passwords |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4267 | Fixed : Register any email address on Facebook Account |
Authorization flaw |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4218 | Same-Origin Policy: From birth until today |
SOP bypass
Browser hacking
CSRF
CORS |
Mozilla
Google (Chrome)
Opera |
Alex Nikolova (@AaylaSecura1138) |
Bug Bounty | 2019-04-04 | 2023-06-13 |
4102 | Stealing Cookies to Login in any Account |
Cookie theft |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-16 | 2023-06-13 |
4098 | Bypassing XSS filter and Stealing User Payment Data |
XSS |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-17 | 2023-06-13 |
4091 | Account Takeover with Clickjacking |
Clickjacking |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-19 | 2023-06-13 |
4084 | $1800 worth Clickjacking |
Clickjacking |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-21 | 2023-06-13 |
4074 | CORS To CSRF Attack |
CORS misconfiguration
CSRF |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-27 | 2023-06-13 |
4044 | Cracking my windshield and earning $10,000 on the Tesla Bug Bounty Program |
Blind XSS |
Tesla |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-07-14 | 2023-06-13 |
3953 | How i was able to exploit the same endpoint 2 times ( multiple xss & open Redirection on 10 subdomain) |
XSS
Open redirect |
Sanity.io |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2019-08-26 | 2023-06-13 |
3936 | Exploiting JSONP and Bypassing Referer Check |
Information disclosure
JSONP |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-09-07 | 2023-06-13 |
3900 | Analysis of CVE-2019-14994 – Jira Service Desk Path Traversal leads to Massive Information Disclosure |
Path traversal |
Atlassian |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-09-25 | 2023-06-13 |
3887 | How “Recon” helped Samsung protect their production repositories of SamsungTv, eCommerce / eStores |
Information disclosure |
Samsung |
Prateek Tiwari |
Bug Bounty | 2019-10-05 | 2023-06-13 |