1029 | “Hey Siri, follow that car!” - How traffic cameras expose your location through parking apps. |
Information disclosure
Session hijacking |
NA |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2022-09-26 | 2023-06-13 |
921 | Broken Link Hijacking — My Second Finding on Hackerone! |
Broken link hijacking |
NA |
mehedishakeel (@mehedishakeel) |
Bug Bounty | 2022-10-23 | 2023-06-13 |
902 | Attacking The Software Supply Chain With A Simple Rename |
Repojacking
Supply chain attack |
GitHub |
Aviad Gershon (@aviadgershon) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
899 | Hijacking AUR Packages by Searching for Expired Domains |
Subdomain takeover
Supply chain attack |
NA |
Joren Vrancken |
Bug Bounty | 2022-10-26 | 2023-06-13 |
869 | Invitation Hijacking |
Authorization flaw
Privilege escalation |
NA |
vFlexo (@vflexo) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
809 | SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover |
Account takeover
Azure AD
Cloud |
Microsoft |
Tomer Nahum (@TomerNahum1) |
Bug Bounty | 2022-11-18 | 2023-06-13 |
802 | Email Graffiti: hacking old email |
Broken link hijacking |
Google (Youtube) |
Dylan Ayrey (@insecurenature) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
730 | Hijacking GitHub Repositories by Deleting and Restoring Them |
Repojacking |
GitHub |
Joren Vrancken |
Bug Bounty | 2022-12-04 | 2023-06-13 |
674 | How I got a 4 digits(₹) bounty from an Indian company |
Broken link hijacking |
NA |
RV Sharma |
Bug Bounty | 2022-12-20 | 2023-06-13 |
634 | Subdomain Hijacking Of Any Qwilr’s Customer |
Subdomain takeover |
NA |
Prial Islam Khan (@prial261) |
Bug Bounty | 2023-01-01 | 2023-06-13 |
632 | $500 in 5 minutes |
Broken link hijacking |
Dropbox |
CoffeeAddict |
Bug Bounty | 2023-01-01 | 2023-06-13 |
554 | CVE-2023-24068 && CVE-2023-24069: Abusing Signal Desktop Client for fun and for Espionage |
Thick client
Insecure data storage
Local Privilege Escalation |
Signal |
John Jackson (@johnjhacking) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
484 | How I Got +1000$ by Clickjacking |
Clickjacking |
NA |
W13DOM |
Bug Bounty | 2023-02-07 | 2023-06-13 |
480 | Chaining Bugs to get my First Bug Bounty |
CSRF
Open redirect
Clickjacking
Account takeover |
NA |
ag3n7 (@ag3n7apk) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
453 | LPE via StorSvc |
Local Privilege Escalation
DLL Hijacking |
Microsoft (Windows) |
Antón Ortigueira (@antuache) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
375 | Broken links hijacking and CDN takeover |
Broken link hijacking
Subdomain takeover |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2023-02-28 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
261 | Dynamic Linking Injection and LOLBAS Fun |
DLL Hijacking
Dynamic-linking injection
Local Privilege Escalation |
NA |
Joseph Henry |
Bug Bounty | 2023-03-28 | 2023-06-13 |
212 | Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories |
Repojacking
Supply chain attack |
NA |
Joren Vrancken |
Bug Bounty | 2023-04-10 | 2023-06-13 |
139 | Azure Devops CICD Pipelines - Command Injection With Parameters, Variables And A Discussion On Runner Hijacking |
CI/CD
OS command injection
RCE |
Microsoft (Azure DevOps Pipelines) |
Sana Oshika (@bigshika) |
Bug Bounty | 2023-05-01 | 2023-06-13 |
101 | Rendezvous with a Chatbot: Chaining Contextual Risk Vulnerabilities |
Chatbot
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Captcha bypass |
NA |
Abeer Banerjee (@bugasur) |
Bug Bounty | 2023-05-11 | 2023-06-13 |
96 | CS:GO: From Zero to 0-day |
Game hacking
RCE
Memory corruption
Arbitrary file download
Arbitrary file write
DLL Hijacking
Privilege Escalation |
Valve (CS:GO) |
Felipe |
Bug Bounty | 2023-05-13 | 2023-06-13 |
81 | DLL Hijacking Strikes Back: Exploiting Windows on ARM RDP Client (CVE-2023-24905) |
DLL Hijacking
Local Privilege Escalation |
Microsoft (Windows) |
Dor Dali |
Bug Bounty | 2023-05-17 | 2023-06-13 |