3858 | Cross Site Request Forgery Critical Exploitable IN Infected Site? |
CSRF |
NA |
Hossam Mesbah |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3853 | Filling in the Blanks: Exploiting Null Byte Buffer Overflow for a $40,000 Bounty |
Null byte buffer overflow
Memory corruption |
NA |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-11-01 | 2023-06-13 |
3806 | Reflected XSS in graph.facebook.com leads to account takeover in IE/Edge |
Reflected XSS
Account takeover |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2019-11-27 | 2023-06-13 |
3662 | Exploiting WebSocket [Application Wide XSS / CSRF] |
XSS
CSRF |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3593 | EN | Administrator level Privilege Escalation story |
Privilege escalation |
NA |
Samet Sahin (@sametsahinnet) |
Bug Bounty | 2020-03-19 | 2023-06-13 |
3547 | Multiple Kernel Vulnerabilities Affecting All Qualcomm Devices |
Memory corruption
Race condition |
Qalcomm
Samsung |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2020-04-15 | 2023-06-13 |
3539 | Abusing HTTP Path Normalization and Cache Poisoning to steal Rocket League accounts |
HTTP cache poisoning
Open redirect |
Rocket League |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-04-19 | 2023-06-13 |
3513 | Hacking Razer Pay Ewallet App |
IDOR |
Razer |
Richard Tan (@sambal0x) |
Bug Bounty | 2020-04-30 | 2023-06-13 |
3382 | A subtle stored-XSS in WordPress core |
Stored XSS
RCE |
WordPress |
Sam Thomas (@_s_n_t) |
Bug Bounty | 2020-06-17 | 2023-06-13 |
3377 | Hacking Starbucks and Accessing Nearly 100 Million Customer Records |
Path traversal |
Starbucks |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3269 | XSS, RCE & HTML File Upload in same endpoint |
XSS
RCE
Unrestricted file upload |
NA |
Tarikul Islam (@sa1tama0) |
Bug Bounty | 2020-07-29 | 2023-06-13 |
3217 | Open Sesame: Escalating Open Redirect to RCE with Electron Code Review |
Open redirect
RCE
Security code review |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2020-08-14 | 2023-06-13 |
3121 | Journey Of My First Bug Bounty (Nov 2018) |
Authentication bypass |
Samsung |
Harsh Tyagi (@harshtya9i) |
Bug Bounty | 2020-10-02 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3082 | Samsung S20 - RCE via Samsung Galaxy Store App |
RCE |
Samsung |
F-Secure |
Bug Bounty | 2020-10-23 | 2023-06-13 |
3038 | User’s private watched videos/saved videos exposed through a messenger call from a locked smartphone. |
Information disclosure
Authorization flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3037 | How a simple bug in Facebook Lite let me win my first bug bounty from Facebook |
Information disclosure |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
2958 | Broken Access Control on samsung.com subdomain leads to Mass Account Takeover of Samsung employees application accounts |
Information disclosure
Account takeover
Authorization flaw |
Samsung |
Gal Nagli (@naglinagli) |
Bug Bounty | 2020-12-18 | 2023-06-13 |
2869 | Chaining a self XSS to Account Takeover |
Self-XSS
Reflected XSS
Account takeover |
NA |
Arman Sameer (@ArmanSameer95) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2835 | Page Admin Disclosed In Groups Due To Improper Session Handling In Facebook Web |
Information disclosure |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2818 | Hacking Chess.com and Accessing 50 Million Customer Records |
Reflected XSS
Information disclosure
Account takeover |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2773 | CVE-2021-23827: Sakura Samurai discover cleartext pictures in Keybase Desktop Client; Windows, macOS, Linux |
Unencrypted storage |
Keybase |
John Jackson (@johnjhacking) |
Bug Bounty | 2021-02-22 | 2023-06-13 |
2744 | The Invincible Kid |
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2592 | Facebook account takeover due to unsafe redirects after the OAuth flow |
OAuth
Open redirect
Account takeover |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2590 | How I got $400 for my first SSRF bug? |
SSRF |
NA |
Usama Varikkottil (@usama_dev) |
Bug Bounty | 2021-05-01 | 2023-06-13 |