2540 | Third-Party Apps were still getting your private Facebook data even after their access expiry. |
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2537 | 13 Nagios Vulnerabilities, #7 will SHOCK you! |
RCE
Local Privilege Escalation
XSS
Security code review |
Nagios |
Samir Ghanem (@sam0x21r) |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2497 | How I could have accessed all your private videos/photos saved inside your device without even unlocking it? |
Authorization flaw
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-06-06 | 2023-06-13 |
2490 | Two weeks of securing Samsung devices: Part 1 |
Arbitrary file write
Insecure intent
Android |
Samsung |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-06-10 | 2023-06-13 |
2459 | Stored XSS via Invite leading to Mass Account Takeover at Opera. |
Stored XSS |
Opera |
Samrat Gupta (@Sm4rty_) |
Bug Bounty | 2021-06-20 | 2023-06-13 |
2422 | Whose app are you downloading? Link hijacking Binance’s shortlinks through AppsFlyer |
Broken link hijacking |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-07-10 | 2023-06-13 |
2417 | Broken Access control bug : Bypassing 403’s by finding another endpoint that do the same thing. |
Broken Access Control
403 bypass |
NA |
tomorrowisnew (@tomorrowisnew_) |
Bug Bounty | 2021-07-12 | 2023-06-13 |
2359 | Multi Domain DOM Cross Site Scripting |
DOM XSS |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2358 | Blind XXE Leads to Internal Port Scanning Through SSRF |
XXE
SSRF |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2340 | Size Matters — CVE-2021–0485 (High) |
Local Privilege Escalation
Android |
Google |
Dimitrios Valsamaras (@Ch0pin) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2318 | Two weeks of securing Samsung devices: Part 2 |
Arbitrary file write
Arbitrary file read
Vulnerable Android content provider
Android |
Samsung |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2277 | Two account takeover bugs worth $4300 🎁 |
Account takeover
Privilege escalation
403 bypass
IDOR |
NA |
Usama Varikkottil (@usama_dev) |
Bug Bounty | 2021-08-29 | 2023-06-13 |
2160 | Account Takeover — Story of 2 same issues in a single program but different sub-domains. |
Account takeover |
NA |
Himanshu Pdy (@himanshu_pdy) |
Bug Bounty | 2021-10-10 | 2023-06-13 |
2087 | Simple SSRF Allows Access To Internal Assets |
SSRF |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
1960 | How I Am Able To Crash Anyone’s Mozilla Firefox Browser By Sending An Email |
DoS |
Mozilla |
Sam |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1947 | How i was able to bypass a Pin code Protection |
Authorization flaw |
NA |
Kerolos sameh (@xko2xx) |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1941 | thisclosed_#1 - Full Account Takeover of ANY user via Insecure Direct Object Reference (IDOR) on reset password functionality |
IDOR
Password reset
Account takeover |
NA |
Samuele Gugliotta (@indevi0us) |
Bug Bounty | 2022-01-04 | 2023-06-13 |
1934 | A Tale Of 5250$: How I Accessed Millions Of User’s Data Including Their National ID’s |
AWS misconfiguration
Information disclosure |
NA |
Sam (@__Sam0_0) |
Bug Bounty | 2022-01-07 | 2023-06-13 |
1915 | XXE in SAML SSO Writeup - Bug Bounty |
XXE |
NA |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-01-16 | 2023-06-13 |
1865 | CVE-2021-44142: Details On A Samba Code Execution Bug Demonstrated At Pwn2Own Austin |
Memory corruption
RCE |
NA |
Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss) |
Bug Bounty | 2022-02-01 | 2023-06-13 |
1792 | How I could’ve bypassed the 2FA security of Instagram once again? |
MFA bypass
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2022-02-21 | 2023-06-13 |
1703 | When Equal is Not, Another WebView Takeover Story |
Android |
NA |
Dimitrios Valsamaras (@Ch0pin) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1669 | Hacked Instagram Handle Of Samsung…. |
Broken link hijacking |
Samsung |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-03 | 2023-06-13 |
1611 | Adobe Acrobat hollowing out same-origin policy |
XSS
SOP bypass
Open redirect
postMessage |
Adobe |
Wladimir Palant (@WPalant) |
Bug Bounty | 2022-04-19 | 2023-06-13 |
1593 | Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054) |
SSRF |
VMware |
Keiran Sampson (@hpy_downunder) |
Bug Bounty | 2022-04-27 | 2023-06-13 |