571 | Azure Active Directory Flaw Allowed SAML Persistence |
Azure AD
SAML
SSO |
Microsoft (Azure) |
Secureworks Counter Threat Unit (@Secureworks) |
Bug Bounty | 2023-01-18 | 2023-06-13 |
568 | The easiest way I used to bypass an admin panel |
HTTP request smuggling
Account takeover |
NA |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
567 | CVE-2022-47966 SAML ShowStopper |
SAML
XSLT injection |
Zoho (ManageEngine) |
Khoa Dinh (@_l0gg) |
Bug Bounty | 2023-01-19 | 2023-06-13 |
563 | Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434) |
Android
Insecure intent
Insecure deeplink
URL validation bypass |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
479 | Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization |
Insecure deserialization
RCE
Security code review |
Inductive Automation Ignition |
Piotr Bazydło (@chudyPB) |
Bug Bounty | 2023-02-08 | 2023-06-13 |
457 | Bypassing SameSite=lax cookie restrictions to preform CSRF resulting to a horizontal privilege escalation via poor email verification mechanism |
CSRF |
NA |
Imad Husanovic (@deadoverflow_) |
Bug Bounty | 2023-02-13 | 2023-06-13 |
432 | [1500$ Worth — Slack] vulnerability, bypass invite accept process |
Broken Access Control
Logic flaw |
Slack |
Sirat Sami (@siratsami71) |
Bug Bounty | 2023-02-20 | 2023-06-13 |
393 | Unauthenticated GraphQL Introspection and API calls |
GraphQL
Missing authentication |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
392 | How I got a $2000 bounty with RXSS |
Reflected XSS |
NA |
Hashir Sami Khan (@P4n7h3Rx) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
220 | A web security story from 2008: silently securing JSON.parse |
Parsing issue
XSS
Arbitrary Code Execution |
JSON.parse |
Mike Samuel (@mvsamuel) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
200 | TOPdesk vulnerable to XML Signature Wrapping Attacks |
XML Signature Wrapping
SAML
SSO |
TOPdesk |
Paulo A. Silva (@pauloasilva_com) |
Bug Bounty | 2023-04-12 | 2023-06-13 |
182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
173 | The Fuzzing Guide to the Galaxy: An Attempt with Android System Services |
Android
Fuzzing
Heap overflow
Integer overflow
Out-of-bounds Write
Memory corruption
Local Privilege Escalation |
Samsung |
Anthony Remy |
Bug Bounty | 2023-04-20 | 2023-06-13 |
148 | Redash SAML Authentication Bypass |
SAML
Authentication bypass |
Redash |
An Trinh (@_tint0) |
Bug Bounty | 2023-04-28 | 2023-06-13 |
55 | XSS Via Qr Code |
XSS |
NA |
Ahmed Osama (A0G) |
Bug Bounty | 2023-05-25 | 2023-06-13 |