2243 | 5 Different Vulnerabilities in Google’s Threadit |
DOM XSS
Clickjacking
Privilege escalation
Information disclosure |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2204 | Cookie Stealing via Clickjacking using Burp collaborator |
Clickjacking |
NA |
Anurag__Verma |
Bug Bounty | 2021-09-22 | 2023-06-13 |
2186 | Zero-Day: Hijacking iCloud Credentials with Apple Airtags (Stored XSS) |
Stored XSS |
Apple |
Bobby Rauch / Bobbyr |
Bug Bounty | 2021-09-28 | 2023-06-13 |
2079 | Broken Link Hijacking — 404 Google Play Store— xxx$ Bounty |
Broken link hijacking |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2021-11-14 | 2023-06-13 |
2060 | Peeping through a Web-Socket |
Cross-Site Websocket Hijacking (CSWH) |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2021-11-21 | 2023-06-13 |
2044 | [socket.io] Cross-Site Websockets Hijacking |
Cross-Site Websocket Hijacking (CSWH) |
Node.js third-party modules |
sh1yo (@sh1yo_) |
Bug Bounty | 2021-11-29 | 2023-06-13 |
1929 | Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle%27s Shibboleth |
Session hijacking
Session management issue
Account takeover
RCE |
Moodle |
Johannes Moritz |
Bug Bounty | 2022-01-10 | 2023-06-13 |
1926 | Attacking RDP from Inside: How we abused named pipes for smart-card hijacking, unauthorized file system access to client machines and more |
RCE |
Microsoft |
Gabriel Sztejnworcel (@sztejnworcel) |
Bug Bounty | 2022-01-11 | 2023-06-13 |
1924 | Pwning the portal: from database dump to session hijacking |
SQL injection
XSS
CSRF |
NA |
Bitcrack (@bitcrack_cyber) |
Bug Bounty | 2022-01-12 | 2023-06-13 |
1879 | Paytm-Broken Link Hijacking |
Broken link hijacking |
Paytm |
Lohith Gowda M (@lohigowda_in) |
Bug Bounty | 2022-01-29 | 2023-06-13 |
1824 | Broken Link Hijacking - Mr. User-Agent |
Broken link hijacking |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-02-13 | 2023-06-13 |
1669 | Hacked Instagram Handle Of Samsung…. |
Broken link hijacking |
Samsung |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-03 | 2023-06-13 |
1562 | The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… |
CSS injection
Clickjacking
Account takeover
XSS
Cookie bomb
Self-XSS
CSRF |
NA |
Renwa (@RenwaX23) |
Bug Bounty | 2022-05-10 | 2023-06-13 |
1537 | Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web |
Account takeover
Pre-hijacking attack |
Dropbox
Meta / Facebook
LinkedIn
WordPress
Zoom |
Avinash Sudhodanan (@sudoavi) |
Bug Bounty | 2022-05-20 | 2023-06-13 |
1532 | Vulnerability In PayPal worth 200000$ bounty, Attacker can Steal Your Balance by One-Click |
Clickjacking |
Paypal |
Souhaib Naceri (@h4x0r_dz) |
Bug Bounty | 2022-05-22 | 2023-06-13 |
1521 | Hijacking Over 100k GoDaddy Websites |
Subdomain takeover |
GoDaddy |
Jonathan Cran (@jcran) |
Bug Bounty | 2022-05-25 | 2023-06-13 |
1518 | Social Media Take Over = Easy Money |
Broken link hijacking |
NA |
Jesse Clark (@Hogarth45_) |
Bug Bounty | 2022-05-26 | 2023-06-13 |
1395 | Account hijacking using "dirty dancing" in sign-in OAuth-flows |
OAuth
Account takeover |
NA |
Frans Rosén (@fransrosen) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1377 | Microsoft Azure Site Recovery DLL Hijacking |
DLL Hijacking
Privilege escalation |
Microsoft |
Jimi Sebree (@DinoBytes) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1376 | CVE-2022-32223 Discovery: DLL Hijacking via npm CLI |
DLL Hijacking
Privilege escalation |
Node.js |
Yakir Kadkoda |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1322 | How I Gained Access To A Finance Company’s Accounts (Session Hijacking) |
Session fixation
Weak crypto |
NA |
Talha Karakumru |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1281 | Hijacking email with Cloudflare Email Routing |
HTTP response manipulation
Privilege escalation |
NA |
Albert Pedersen (@AlbertSPedersen) |
Bug Bounty | 2022-08-03 | 2023-06-13 |
1149 | Vulnerability in TikTok Android app could lead to one-click account hijacking |
Insecure deeplink
Android |
TikTok |
Microsoft 365 Defender Research Team |
Bug Bounty | 2022-08-31 | 2023-06-13 |
1076 | Abusing Broken Link In Fitbit (Google Acquisition)To Collect BugBounty Reports On Behalf Of Google ! |
Broken link hijacking |
Google |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2022-09-16 | 2023-06-13 |
1073 | How i made the multiple hall of fame in Nokia within 2 minutes |
Clickjacking |
Nokia |
Vedavyasan |
Bug Bounty | 2022-09-17 | 2023-06-13 |