3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3302 | I am able to see user’s sensitive data through JSON file. |
Information disclosure
Authorization flaw |
NA |
Saurabh siddharam sanmane (@saurabhsanmane2) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3298 | Android pin bypass with rate limiting |
Lack of rate limiting
Authentication bypass |
NA |
Baluz (@t3chman) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3297 | Creative Android pin bypass with Race conditon |
Race condition
Authentication bypass |
NA |
Baluz (@t3chman) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3296 | Unique Case for Price Manipulation | BugBounty | VAPT |
Payment tampering |
NA |
Harshit Sengar (@sengarharshit1) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3294 | bypass user-restriction registration |
Logic flaw
Payment tampering |
NA |
Mohamed Ayad |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3293 | Chaining rate limiting for account lockout |
Lack of rate limiting |
NA |
Sandip Oli |
Bug Bounty | 2020-07-19 | 2023-06-13 |
3292 | DOS over wep application |
DoS |
NA |
Mohamed Ayad |
Bug Bounty | 2020-07-19 | 2023-06-13 |
3290 | Denial of Service(DoS) By Regex |
DoS |
NA |
Ashik B |
Bug Bounty | 2020-07-20 | 2023-06-13 |
3289 | Increasing reward points N number of time |
Logic flaw |
NA |
Saddam Hussain (@wisdomfreak1) |
Bug Bounty | 2020-07-21 | 2023-06-13 |
3288 | Hack Till Your Last Breath |
IDOR |
NA |
mechboy / _m.u.h.e_ (@Muhe76355002) |
Bug Bounty | 2020-07-21 | 2023-06-13 |
3286 | HTTP Parameter Pollution - It’s Contaminated |
HTTP parameter pollution |
NA |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-07-24 | 2023-06-13 |
3285 | Hunting Android Application Bugs Using Android Studio. |
Authorization flaw
Client-side enforcement of server-side security
Information disclosure |
NA |
Tarek Mohammed (@Conan0x3) |
Bug Bounty | 2020-07-24 | 2023-06-13 |
3284 | A $5000 Account Takeover |
Account takeover
Password reset |
NA |
neelam |
Bug Bounty | 2020-07-25 | 2023-06-13 |
3283 | DNS Rebinding, The treacherous attack it can be |
DNS rebinding |
NA |
Vuk Ivanovic |
Bug Bounty | 2020-07-25 | 2023-06-13 |
3282 | A Simple IDOR which should not be missed on dating site ;) |
IDOR
Information disclosure |
NA |
neelam |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3281 | Obtained a bunch of sensitive data in just few steps — Hacking |
AWS misconfiguration
Information disclosure |
NA |
Airlangga Visnhu Murthi |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3280 | How I bypassed 2fa in a 3 years old private program! |
MFA bypass
Bruteforce
Lack of rate limiting |
NA |
Shivangx01b (@shivangx01b) |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3279 | An unreproducable bug due to the load balancer, an unusual Open Redirect bug |
Open redirect |
NA |
tololovejoi (@tolo7010) |
Bug Bounty | 2020-07-27 | 2023-06-13 |
3277 | CVE-2020–9934: Bypassing the macOS Transparency, Consent, and Control (TCC) Framework for unauthorized access to sensitive user data |
MacOS
Local Privilege Escalation
Authorization flaw |
Apple |
Matt Shockley (@mattshockl) |
Bug Bounty | 2020-07-27 | 2023-06-13 |
3276 | CSRF + Open Redirect To Account Takeover |
CSRF
Open redirect
Account takeover |
NA |
R29k (@R29k_) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3274 | Pre-Access to Victim’s Account via Facebook Signup |
OAuth
Account takeover |
NA |
Akshansh Jaiswal (@Akshanshjaiswl) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3273 | Authentication Token Leads To IDOR |
Authentication bypass |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3272 | Company’s zendesk subdomain lead to hidden access. |
Exposed registration page |
NA |
himanshu pdy (@himanshu_pdy) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3271 | Authorization bypass in Google’s ticketing system (Google-GUTS) |
Authorization flaw |
Google |
Zohar Shachar |
Bug Bounty | 2020-07-28 | 2023-06-13 |