Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1583CVE-2022-25262 | JetBrains Hub single-click SAML response takeover Authorization flaw SAML OAuth JetBrains Yurii Sanin (@SaninYurii) Bug Bounty2022-05-032023-06-13
1577Samsung Flow - Any App Can Read The External Storage Android Insecure intent Samsung Ken Gannon (@Yogehi) Bug Bounty2022-05-042023-06-13
1576Samsung Galaxy - Any App Can Install Any App In The Galaxy App Store Android Insecure intent Samsung Ken Gannon (@Yogehi) Bug Bounty2022-05-042023-06-13
1564RCE via Dependency Confusion Dependency confusion NA Samrat Gupta (@Sm4rty_) Bug Bounty2022-05-102023-06-13
1516Bygone Vulnerabilities - Remote Code Execution in IBM Lotus SameTime Clients (CVE-2013-0553) XSS RCE IBM Brian (@hoyahaxa) Bug Bounty2022-05-272023-06-13
1509Bypass CSP Using WordPress By Abusing Same Origin Method Execution CSP bypass Same Origin Method Execution WordPress Paulos Yibelo (@PaulosYibelo) Bug Bounty2022-05-292023-06-13
1479Same bug different platform Logic flaw Authorization flaw Meta / Facebook Prajwol Dhungana (@PrajwolDhunga14) Bug Bounty2022-06-112023-06-13
1407Two faces of a same PDF document PDF parser differential attack Mozilla Google Adobe Toni Huttunen Bug Bounty2022-07-012023-06-13
1348Hacking Facebook Invoice: How I could’ve bought anything for Free from Facebook Business Pages Payment bypass Meta / Facebook Samip Aryal (@samiparyal_) Bug Bounty2022-07-182023-06-13
1344How i was able to bypass Open Redirect 3 times on same program. Open redirect NA himanshu pdy (@himanshu_pdy) Bug Bounty2022-07-192023-06-13
1261The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I) Memory corruption Race condition Local Privilege Escalation Android Linux Kernel Organization Google Samsung Xingyu Jin Bug Bounty2022-08-102023-06-13
1243Amazon Cognito misconfiguration lead to account takeover Account takeover NA Hossam Ahmed (@iknowhatodo0x01) Bug Bounty2022-08-122023-06-13
1213CSRF leads to Account Takeover | Samsung CSRF Account takeover Samsung R ando (@Rando02355205) Bug Bounty2022-08-162023-06-13
1170My Hall of Fame at United Nations Success Story XSS United Nations Joshua Arulsamy (@Joshua_Arulsamy) Bug Bounty2022-08-272023-06-13
1052Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library Universal XSS SSRF Open redirect Web cache poisoning Netlify Gemini PancakeSwap Docusign Moonpay Celo Sam Curry (@samwcyo) Bug Bounty2022-09-212023-06-13
962Fall account takeover via Amazon Cognito misconfiguration IDOR Account takeover NA Hossam Ahmed (@iknowhatodo0x01) Bug Bounty2022-10-132023-06-13
903SSD Advisory – Galaxy Store Applications Installation/Launching without User Interaction XSS Samsung - Bug Bounty2022-10-262023-06-13
873Gregor Samsa: Exploiting Java%27s XML Signature Verification Integer truncation RCE SAML OpenJDK Apache Commons BCEL Felix Wilhelm (@_fel1x) Bug Bounty2022-11-022023-06-13
868Case of Admin Bypass for RCE, XSS, and Information Disclosure RCE Unrestricted file upload Stored XSS Information disclosure NA Sam Paredes (@caffeinevulns) Bug Bounty2022-11-032023-06-13
843Discovering vendor-specific vulnerabilities in Android Android Samsung Google Oversecured (@OversecuredInc) Bug Bounty2022-11-102023-06-13
822Chromium: Same Origin Policy bypass within a single site a.k.a. "Google Roulette" SOP bypass Browser hacking Google (Chromium) Michał Bentkowski (@SecurityMB) Bug Bounty2022-11-162023-06-13
761Broken access control + misconfiguration = Beautiful privilege escalation Broken Access Control Privilege escalation NA Hossam Mesbah (@m359ah) Bug Bounty2022-11-282023-06-13
684Simple CORS misconfig leads to disclose the sensitive token worth of $$$ CORS misconfiguration Token leak Linear Ramalingasamy Bug Bounty2022-12-162023-06-13
621Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More Account takeover SSO RCE Authorization bypass SQL injection Mass assignment Information disclosure Kia Honda Infiniti Nissan Acura Mercedes-Benz Hyundai Genesis BMW Rolls Royce Ferrari Spireon Ford Reviver Porsche Toyota Jaguar Land Rover SiriusXM Sam Curry (@samwcyo) Bug Bounty2023-01-032023-06-13
588thisclosed_#2 - PostgreSQL Database Exfiltration through the abuse of PostgREST requests SQL injection NA Samuele Gugliotta (@indevi0us) Bug Bounty2023-01-162023-06-13