readme.md
January 20, 2023 · View on GitHub
Title
Root Remote Code Execution on https://███
URL
https://hackerone.com/reports/632721
Severity score
null
Reporter
cdl
Bounty paid
null
Title
Java RMI (Remote Code Execution)
URL
https://hackerone.com/reports/163547
Severity score
null
Reporter
leba
Bounty paid
null
Title
http://fitter1.i.mail.ru/browser/ торчит Graphite в мир
URL
https://hackerone.com/reports/60573
Severity score
null
Reporter
isox
Bounty paid
$400
Title
potential RCE and XSS via file upload requiring user account and default settings
URL
https://hackerone.com/reports/678727
Severity score
8.8
Reporter
rcejules
Bounty paid
null
Title
URGENT - Subdomain Takeover in support.urbandictionary.com pointing to Zendesk
URL
https://hackerone.com/reports/103432
Severity score
null
Reporter
harry_mg
Bounty paid
null
Title
php mcrypt ext - In correct casting from size_t to int lead to heap overflow in mdecrypt_generic
URL
https://hackerone.com/reports/152400
Severity score
null
Reporter
minhrau
Bounty paid
$1,000
Title
SQL injection on contactws.contact-sys.com in TRateObject.AddForOffice in USER_ID parameter leads to remote code execution
URL
https://hackerone.com/reports/816560
Severity score
10
Reporter
honoki
Bounty paid
$1,000
Title
ownCloud 2.2.2.6192 DLL Hijacking Vulnerability
URL
https://hackerone.com/reports/151475
Severity score
null
Reporter
lionheartrox
Bounty paid
$50
Title
The “Malstaller” Attack, global hijacking of any installation process to achieve RCE with elevated privileges, Windows OS (vendor agnostic)
URL
https://hackerone.com/reports/165969
Severity score
null
Reporter
penrose
Bounty paid
null
Title
URGENT - SUBDOMAIN TAKEOVER ON TWITTER ACQ.
URL
https://hackerone.com/reports/44578
Severity score
null
Reporter
simon90
Bounty paid
null
Title
Image lib - unescaped file path
URL
https://hackerone.com/reports/250273
Severity score
null
Reporter
freetom
Bounty paid
null
Title
Windows Privilege Escalation: Malicious OpenSSL Engine
URL
https://hackerone.com/reports/608577
Severity score
7.8
Reporter
mirchr
Bounty paid
$200
Title
Prototype pollution attack (mixin-deep)
URL
https://hackerone.com/reports/311236
Severity score
1.8
Reporter
holyvier
Bounty paid
null
Title
Remote Code Execution on █████████
URL
https://hackerone.com/reports/962013
Severity score
null
Reporter
hzllaga
Bounty paid
null
Title
Уязвимость в Указание мест на фото + фича + хакинг
URL
https://hackerone.com/reports/66235
Severity score
null
Reporter
pisarenko
Bounty paid
$200
Title
Insecure implementation of deserialization in cryo
URL
https://hackerone.com/reports/350418
Severity score
8.7
Reporter
greendog
Bounty paid
null
Title
Remote command execution (RCE) vulnerability on a DoD website
URL
https://hackerone.com/reports/202652
Severity score
null
Reporter
japp1
Bounty paid
null
Title
Remote Code Execution (RCE) vulnerability in multiple DoD websites
URL
https://hackerone.com/reports/231687
Severity score
null
Reporter
joaomatosf
Bounty paid
null
Title
TOCTTOU bug in mrb_str_setbyte leading the memory corruption
URL
https://hackerone.com/reports/181893
Severity score
null
Reporter
raydot
Bounty paid
$20,000
Title
One Click Remote Code Injection - *.blog.newrelic.com
URL
https://hackerone.com/reports/941421
Severity score
null
Reporter
arsene_lupin
Bounty paid
$506.78
Title
Server-side include injection vulnerability in a DoD website
URL
https://hackerone.com/reports/192931
Severity score
null
Reporter
jutsuce
Bounty paid
null
Title
integer overflow in urlencode caused heap corruption
URL
https://hackerone.com/reports/159960
Severity score
null
Reporter
minhrau
Bounty paid
$500
Title
Local file read in image editor
URL
https://hackerone.com/reports/122475
Severity score
null
Reporter
sl1m
Bounty paid
$5,000
Title
Remote code execution (RCE) in multiple DoD websites
URL
https://hackerone.com/reports/226245
Severity score
null
Reporter
joaomatosf
Bounty paid
null
Title
Client-side Template Injection in Search, user email/token leak and maybe sandbox escape
URL
https://hackerone.com/reports/271960
Severity score
null
Reporter
europa
Bounty paid
$500
Title
Possible xWork classLoader RCE: shared.mail.ru
URL
https://hackerone.com/reports/67161
Severity score
null
Reporter
isox
Bounty paid
$200
Title
chrome://brave can still be navigated to, leading to RCE
URL
https://hackerone.com/reports/415178
Severity score
null
Reporter
qab
Bounty paid
$300
Title
Subdomain Takeover in http://assets.goubiquiti.com/
URL
https://hackerone.com/reports/109699
Severity score
null
Reporter
c1231665
Bounty paid
$500
Title
Code Injection Vulnerability in dot Package
URL
https://hackerone.com/reports/390929
Severity score
7.4
Reporter
cris_semmle
Bounty paid
null
Title
msilib.OpenDatabase Type Confusion
URL
https://hackerone.com/reports/167688
Severity score
null
Reporter
johnleitch
Bounty paid
$1,000
Title
Desktop app RCE (#276031 bypass)
URL
https://hackerone.com/reports/843171
Severity score
null
Reporter
ivarsvids
Bounty paid
null
Title
Content injection via URL parameter.
URL
https://hackerone.com/reports/263913
Severity score
null
Reporter
johnh4x0r
Bounty paid
null
Title
HTML Injection on airlink.ubnt.com
URL
https://hackerone.com/reports/226783
Severity score
null
Reporter
ruisilva
Bounty paid
$100
Title
DLL Hijacking in Synapse 2 CrashSender1402.exe via version.dll
URL
https://hackerone.com/reports/702252
Severity score
7.1
Reporter
cccaaasser
Bounty paid
$750
Title
Add arbitrary content to Password Reset Email
URL
https://hackerone.com/reports/244677
Severity score
null
Reporter
footstep
Bounty paid
null
Title
Remote code execution as root on [REDACTED]
URL
https://hackerone.com/reports/58914
Severity score
null
Reporter
agarri_fr
Bounty paid
$3,000
Title
RCE due to Web Console IP Whitelist bypass in Rails 4.0 and 4.1
URL
https://hackerone.com/reports/44513
Severity score
null
Reporter
joernchen
Bounty paid
$500
Title
Mercurial can be tricked into granting authorized users access to the Python debugger
URL
https://hackerone.com/reports/222020
Severity score
null
Reporter
claudijd
Bounty paid
$500
Title
Remote Code Execution (Reverse Shell) - File Manager
URL
https://hackerone.com/reports/768322
Severity score
5.1
Reporter
javakhishvili
Bounty paid
null
Title
DOM based XSS on
URL
https://hackerone.com/reports/139875
Severity score
null
Reporter
blackzero
Bounty paid
null
Title
Use of uninitialized memory in unserialize()
URL
https://hackerone.com/reports/195950
Severity score
null
Reporter
rc0r
Bounty paid
$500
Title
NULL pointer dereference in SimpleXMLElement::asXML()
URL
https://hackerone.com/reports/175262
Severity score
null
Reporter
jot
Bounty paid
$500
Title
Type confusion in partial.setstate, partial_repr, partial_call leads to memory corruption, reliable control flow hijack
URL
https://hackerone.com/reports/116286
Severity score
null
Reporter
nedw
Bounty paid
$1,000
Title
PHP openssl_x509_parse() Memory Corruption Vulnerability
URL
https://hackerone.com/reports/523
Severity score
null
Reporter
sesser
Bounty paid
$4,000
Title
RCE in profile picture upload
URL
https://hackerone.com/reports/135072
Severity score
null
Reporter
c666a323be94d57
Bounty paid
$2,500
Title
RCE on a Department of Defense website
URL
https://hackerone.com/reports/184279
Severity score
null
Reporter
dawgyg
Bounty paid
null
Title
[Simplenote for Windows] Client RCE via External JavaScript Inclusion leveraging Electron
URL
https://hackerone.com/reports/291539
Severity score
null
Reporter
ysx
Bounty paid
$250
Title
Server side request forgery on image upload for lists
URL
https://hackerone.com/reports/158016
Severity score
null
Reporter
eboda
Bounty paid
$50
Title
accounts.informatica.com - RCE due to exposed Groovy console
URL
https://hackerone.com/reports/672243
Severity score
null
Reporter
0ang3el
Bounty paid
null
Title
Remote Code Execution (RCE) in a DoD website
URL
https://hackerone.com/reports/213069
Severity score
null
Reporter
daveysec
Bounty paid
null
Title
RCE and Complete Server Takeover of http://www.█████.starbucks.com.sg/
URL
https://hackerone.com/reports/502758
Severity score
10
Reporter
spaceraccoon
Bounty paid
$4,000
Title
Remote client memory corruption in ssl_add_clienthello_tlsext()
URL
https://hackerone.com/reports/175766
Severity score
null
Reporter
guido
Bounty paid
null
Title
Comments Denial of Service in socialclub.rockstargames.com
URL
https://hackerone.com/reports/214370
Severity score
null
Reporter
ramsexy
Bounty paid
$500
Title
Remote Code Execution (RCE) in a DoD website
URL
https://hackerone.com/reports/248116
Severity score
null
Reporter
manoelt
Bounty paid
null
Title
URGENT - Subdomain Takeover on users.tweetdeck.com , the same issue of report #32825
URL
https://hackerone.com/reports/42236
Severity score
null
Reporter
missoum1307
Bounty paid
$420
Title
Regarding [CVE-2016-0752] Possible Information Leak Vulnerability in Action View
URL
https://hackerone.com/reports/113831
Severity score
null
Reporter
jyotisingh
Bounty paid
$1,500
Title
RCE on shared.mail.ru due to "widget" plugin
URL
https://hackerone.com/reports/518637
Severity score
10
Reporter
chaosbolt
Bounty paid
$10,000
Title
Remote Code Execution in Basecamp Windows Electron App
URL
https://hackerone.com/reports/1016966
Severity score
null
Reporter
co0sin
Bounty paid
$1,250
Title
Potential code injection in fun delete_directory
URL
https://hackerone.com/reports/250587
Severity score
null
Reporter
freetom
Bounty paid
null
Title
User Access Control Bypass Via Razer elevated service ( RzKLService.exe ) which loads exe in misconfigured way.
URL
https://hackerone.com/reports/769684
Severity score
null
Reporter
dredd_589
Bounty paid
$750
Title
[notevil] - Sandbox Escape Lead to RCE on Node.js and XSS in the Browser
URL
https://hackerone.com/reports/809012
Severity score
null
Reporter
phra
Bounty paid
null
Title
Remote Code Execution (RCE) in a DoD website
URL
https://hackerone.com/reports/212022
Severity score
null
Reporter
0daystolive
Bounty paid
null
Title
Remote Code Execution on Git.imgur-dev.com
URL
https://hackerone.com/reports/206227
Severity score
null
Reporter
orange
Bounty paid
$2,500
Title
[phpobject in cookie] Remote shell/command execution
URL
https://hackerone.com/reports/141956
Severity score
null
Reporter
static
Bounty paid
$20,000
Title
php curl ext size_t overflow lead to heap corruption
URL
https://hackerone.com/reports/152399
Severity score
null
Reporter
minhrau
Bounty paid
$1,000
Title
[treekill] RCE via insecure command concatenation (only Windows)
URL
https://hackerone.com/reports/703415
Severity score
7.3
Reporter
mik317
Bounty paid
null
Title
Возможность залить шелл на https://widget.operator.mail.ru
URL
https://hackerone.com/reports/304545
Severity score
null
Reporter
danila
Bounty paid
$500
Title
GMP Deserialization Type Confusion Vulnerability [MyBB <= 1.8.3 RCE Vulnerability]
URL
https://hackerone.com/reports/198734
Severity score
null
Reporter
ryat
Bounty paid
$1,500
Title
Arbitrary file read via ffmpeg HLS parser at https://www.flickr.com/photos/upload
URL
https://hackerone.com/reports/487008
Severity score
9.9
Reporter
asad0x01_
Bounty paid
$2,000
Title
links the user may download can be a malicious files
URL
https://hackerone.com/reports/182557
Severity score
null
Reporter
seifelsallamy
Bounty paid
null
Title
Explicit, dynamic render path: Dir. Trav + RCE
URL
https://hackerone.com/reports/46019
Severity score
8.6
Reporter
forced-request
Bounty paid
$500
Title
CSV Injection Via Student Password/Name Leads To Client Side RCE And Reading Client Files
URL
https://hackerone.com/reports/943255
Severity score
null
Reporter
demonia
Bounty paid
null
Title
Code injection in https://www.semrush.com
URL
https://hackerone.com/reports/723707
Severity score
null
Reporter
choan
Bounty paid
$500
Title
Email Server Compromised at secure.lahitapiola.fi
URL
https://hackerone.com/reports/177225
Severity score
null
Reporter
ak1t4
Bounty paid
$750
Title
[npm-git-publish] RCE via insecure command formatting
URL
https://hackerone.com/reports/730121
Severity score
6.8
Reporter
mik317
Bounty paid
null
Title
Unserialize leading to arbitrary PHP function invoke
URL
https://hackerone.com/reports/210741
Severity score
10
Reporter
someguyfromthepast
Bounty paid
$5,000
Title
newrelic.com rails directory traversal vuln
URL
https://hackerone.com/reports/134032
Severity score
null
Reporter
feelgood
Bounty paid
null
Title
Type confusion in wrap_decimal leading to memory corruption
URL
https://hackerone.com/reports/185051
Severity score
null
Reporter
raydot
Bounty paid
$18,000
Title
Phabricator Phame Blog Skins Local File Inclusion
URL
https://hackerone.com/reports/39428
Severity score
null
Reporter
nullsub
Bounty paid
$500
Title
Websites Can Run Arbitrary Code on Machines Running the 'PlayStation Now' Application
URL
https://hackerone.com/reports/873614
Severity score
9.6
Reporter
parsiya
Bounty paid
$15,000
Title
Windows builds with insecure path defaults (CVE-2019-1552)
URL
https://hackerone.com/reports/683318
Severity score
null
Reporter
mirchr
Bounty paid
$500
Title
Remote code execution by hijacking an unclaimed S3 bucket in Rocket.Chat's installation script.
URL
https://hackerone.com/reports/399166
Severity score
null
Reporter
edoverflow
Bounty paid
null
Title
Solution for h15411's CTF challenge
URL
https://hackerone.com/reports/415222
Severity score
9.8
Reporter
herrera
Bounty paid
null
Title
Integer overflow lead to heap corruption in sql_regcase
URL
https://hackerone.com/reports/159958
Severity score
null
Reporter
minhrau
Bounty paid
$500
Title
RCE on facebooksearch.algolia.com
URL
https://hackerone.com/reports/134321
Severity score
null
Reporter
michiel
Bounty paid
$500
Title
[meta-git] RCE via insecure command formatting
URL
https://hackerone.com/reports/728040
Severity score
6.2
Reporter
mik317
Bounty paid
null
Title
code injection, steam chat client
URL
https://hackerone.com/reports/411329
Severity score
null
Reporter
zemnmez
Bounty paid
$750
Title
newsroom.uber.com is vulnerable to 'SOME' XSS attack via plupload.flash.swf
URL
https://hackerone.com/reports/150375
Severity score
null
Reporter
jamesclyde
Bounty paid
$1,000
Title
(Authenticated) RCE by bypassing of the .htaccess blacklist
URL
https://hackerone.com/reports/228825
Severity score
9
Reporter
icewind1991
Bounty paid
null
Title
Several simple remote code execution in pdf-image
URL
https://hackerone.com/reports/781664
Severity score
null
Reporter
gabriel-kimiaie
Bounty paid
null
Title
Request Hijacking Vulnerability in RubyGems 2.6.11 and earlier
URL
https://hackerone.com/reports/218088
Severity score
null
Reporter
claudijd
Bounty paid
$1,000
Title
DLL Hijacking Vulnerability in GlassWireSetup.exe
URL
https://hackerone.com/reports/105977
Severity score
null
Reporter
ericlaw
Bounty paid
$100
Title
[H1-2006 2020] Connecting the dots to send hackers their Bug Bounty
URL
https://hackerone.com/reports/889886
Severity score
null
Reporter
akshansh
Bounty paid
null
Title
Remote code execution using render :inline
URL
https://hackerone.com/reports/113928
Severity score
null
Reporter
kratob2
Bounty paid
$1,500
Title
uber.com may RCE by Flask Jinja2 Template Injection
URL
https://hackerone.com/reports/125980
Severity score
null
Reporter
orange
Bounty paid
$10,000
Title
Trivial age-old heap overflow in 32-bit PHP
URL
https://hackerone.com/reports/112863
Severity score
null
Reporter
jbremer
Bounty paid
$500
Title
Remote Code Execution in Rocket.Chat Desktop
URL
https://hackerone.com/reports/276031
Severity score
null
Reporter
mattaustin
Bounty paid
null
Title
[blamer] RCE via insecure command formatting
URL
https://hackerone.com/reports/772448
Severity score
7.5
Reporter
mik317
Bounty paid
null
Title
Various vulnerabilities ultimately lead to attacker control over FliteThermostat server and access to internal accounting application source code
URL
https://hackerone.com/reports/504355
Severity score
null
Reporter
collinmay
Bounty paid
null
Title
PHP code injection at tz.mail.ru
URL
https://hackerone.com/reports/798135
Severity score
8.1
Reporter
cutoffurmind
Bounty paid
$3,000
Title
[create-git] RCE via insecure command formatting
URL
https://hackerone.com/reports/694471
Severity score
null
Reporter
mik317
Bounty paid
null
Title
Remote Code Execution in Slack desktop apps + bonus
URL
https://hackerone.com/reports/783877
Severity score
null
Reporter
oskarsv
Bounty paid
$1,750
Title
Code Injection Vulnerability in morgan Package
URL
https://hackerone.com/reports/390881
Severity score
6.8
Reporter
cris_semmle
Bounty paid
null
Title
Remote Code Execution in Wordpress Desktop
URL
https://hackerone.com/reports/301458
Severity score
null
Reporter
mattaustin
Bounty paid
$250
Title
RCE in ci.owncloud.com / ci.owncloud.org
URL
https://hackerone.com/reports/98559
Severity score
null
Reporter
tomdev
Bounty paid
null
Title
apps.owncloud.com: Malicious file upload leads to remote code execution
URL
https://hackerone.com/reports/84374
Severity score
null
Reporter
imadchabounia
Bounty paid
null
Title
Directory Traversal
URL
https://hackerone.com/reports/1092
Severity score
null
Reporter
nahamsec
Bounty paid
null
Title
Code Injection in macOS Desktop Client
URL
https://hackerone.com/reports/633262
Severity score
6.4
Reporter
r3ggi-on-h1
Bounty paid
$100
Title
another crash in locale_get_keywords function
URL
https://hackerone.com/reports/180116
Severity score
null
Reporter
jot
Bounty paid
$500
Title
Path traversal, SSTI and RCE on a MailRu acquisition
URL
https://hackerone.com/reports/536130
Severity score
9.8
Reporter
0xc0ffee
Bounty paid
$2,000
Title
Remote Unrestricted file Creation/Deletion and Possible RCE.
URL
https://hackerone.com/reports/191884
Severity score
null
Reporter
zigoo0
Bounty paid
null
Title
REMOTE CODE EXECUTION/LOCAL FILE INCLUSION/XSPA/SSRF, view-source:http://sb*.geo.sp1.yahoo.com/, 4/6/14, #SpringClean
URL
https://hackerone.com/reports/6674
Severity score
null
Reporter
nnwakelam
Bounty paid
$3,000
Title
[FG-VD-17-063] NextCloud Insufficient Attack Protection Vulnerability Notification
URL
https://hackerone.com/reports/232347
Severity score
null
Reporter
yzy9951
Bounty paid
$100
Title
In correct casting from size_t to int lead to heap overflow in mcrypt_generic
URL
https://hackerone.com/reports/152398
Severity score
null
Reporter
minhrau
Bounty paid
$1,000
Title
[git-promise] RCE via insecure command formatting
URL
https://hackerone.com/reports/728047
Severity score
6.2
Reporter
mik317
Bounty paid
null
Title
RCE via Print function [Simplenote 1.1.3 - Desktop app]
URL
https://hackerone.com/reports/358049
Severity score
null
Reporter
luigigubello
Bounty paid
$250
Title
SQL injection on contactws.contact-sys.com in TScenObject action ScenObjects leads to remote code execution
URL
https://hackerone.com/reports/816254
Severity score
10
Reporter
honoki
Bounty paid
$5,500
Title
Remote Code Execution in NovaStor NovaBACKUP DataCenter backup software (Hiback)
URL
https://hackerone.com/reports/138824
Severity score
null
Reporter
nyymi
Bounty paid
$100
Title
CSS Injection to disable app & potential message exfil
URL
https://hackerone.com/reports/679969
Severity score
4.3
Reporter
fletchto99
Bounty paid
$500
Title
Stack-based buffer overflow vulnerability in php_stream_zip_opener
URL
https://hackerone.com/reports/152278
Severity score
null
Reporter
knight9
Bounty paid
$1,000
Title
Code injection possible with malformed Nextcloud Talk chat commands
URL
https://hackerone.com/reports/851807
Severity score
8
Reporter
covert-spectre
Bounty paid
$3,000
Title
chrome://brave navigation from web
URL
https://hackerone.com/reports/415967
Severity score
null
Reporter
qab
Bounty paid
$650
Title
potential remote code execution with phar archive
URL
https://hackerone.com/reports/126652
Severity score
null
Reporter
vah13
Bounty paid
$500
Title
ICQ 10.0.12371 icq: Uri Handler '-testability' URL File Insecure Library Loading Code Execution Vulnerability
URL
https://hackerone.com/reports/406702
Severity score
7
Reporter
bigshape
Bounty paid
$500
Title
Use-after-free vulnerability in SPL(SplObjectStorage, unserialize)
URL
https://hackerone.com/reports/114079
Severity score
null
Reporter
seanhn
Bounty paid
$1,000
Title
crash in locale_compose() function
URL
https://hackerone.com/reports/180814
Severity score
null
Reporter
jot
Bounty paid
$500
Title
H1514 Server Side Template Injection in Return Magic email templates?
URL
https://hackerone.com/reports/423541
Severity score
null
Reporter
zombiehelp54
Bounty paid
$10,000
Title
Modify Host Header which is sent to email
URL
https://hackerone.com/reports/791293
Severity score
null
Reporter
codermak
Bounty paid
null
Title
[marketplace.informatica.com] - Template Injection
URL
https://hackerone.com/reports/299241
Severity score
null
Reporter
samengmg
Bounty paid
null
Title
bgplay.mail.ru
URL
https://hackerone.com/reports/122932
Severity score
null
Reporter
isox
Bounty paid
$200
Title
XML Parser Bug: XXE over which leads to RCE
URL
https://hackerone.com/reports/55431
Severity score
null
Reporter
sasi2103
Bounty paid
$700
Title
missing NULL check in dom_document_save_html
URL
https://hackerone.com/reports/175260
Severity score
null
Reporter
jot
Bounty paid
$500
Title
HTML Injection on https://www.mycrypto.com/
URL
https://hackerone.com/reports/326697
Severity score
null
Reporter
t-pwn
Bounty paid
null
Title
Review remote code execution in SwiftMailer
URL
https://hackerone.com/reports/194564
Severity score
null
Reporter
lukasreschke
Bounty paid
null
Title
Use after free vulnerability in mruby Array#to_h causing DOS possible RCE
URL
https://hackerone.com/reports/181321
Severity score
null
Reporter
isra17
Bounty paid
$20,000
Title
macaddress concatenates unsanitized input into exec() command
URL
https://hackerone.com/reports/319467
Severity score
10
Reporter
chalker
Bounty paid
null
Title
Remote code execution vulnerability on a DoD website
URL
https://hackerone.com/reports/192567
Severity score
null
Reporter
korprit
Bounty paid
null
Title
[FG-VD-17-115] Mail.ru's Amigo Browser DLL Pre-Loading Vulnerability Notification
URL
https://hackerone.com/reports/246663
Severity score
6.3
Reporter
kushal89shah
Bounty paid
null
Title
Remote File Upload Vulnerability in business-blog.zomato.com
URL
https://hackerone.com/reports/114389
Severity score
null
Reporter
missoum1307
Bounty paid
null
Title
Mass Assignment Vulnerability in partners.uber.com
URL
https://hackerone.com/reports/99424
Severity score
null
Reporter
rohk
Bounty paid
$1,000
Title
'Limited' RCE in certain places where Liquid is accepted
URL
https://hackerone.com/reports/98259
Severity score
null
Reporter
brakhane
Bounty paid
$1,500
Title
WordPress SOME bug in plupload.flash.swf leading to RCE
URL
https://hackerone.com/reports/134738
Severity score
null
Reporter
cure53
Bounty paid
$1,337
Title
EIP control using type confusion in json encoding
URL
https://hackerone.com/reports/112855
Severity score
null
Reporter
pakt_
Bounty paid
$1,000
Title
Control characters incorrectly handled on Crew Status Update
URL
https://hackerone.com/reports/232499
Severity score
null
Reporter
zuhnny1
Bounty paid
$250
Title
(Critical) Remote Code Execution Through Old TinyMCE upload bypass
URL
https://hackerone.com/reports/778629
Severity score
null
Reporter
konqi
Bounty paid
null
Title
crash in locale_get_keywords() when keyword value in locale string too long
URL
https://hackerone.com/reports/180115
Severity score
null
Reporter
jot
Bounty paid
$500
Title
Panorama UI XSS leads to Remote Code Execution via Kick/Disconnect Message
URL
https://hackerone.com/reports/631956
Severity score
null
Reporter
shayhelman
Bounty paid
$9,000
Title
Java Debug Console Provides Command Injection Without Privellage Esclation
URL
https://hackerone.com/reports/767482
Severity score
null
Reporter
rpbeast33
Bounty paid
null
Title
Docker image with FPM is vulnerable to CVE-2019-11043
URL
https://hackerone.com/reports/720306
Severity score
9.8
Reporter
beched
Bounty paid
$100
Title
Remote code executio in NPM package getcookies
URL
https://hackerone.com/reports/346516
Severity score
10
Reporter
tiblu
Bounty paid
null
Title
Arbitrary code execution in desktop client via OpenSSL config
URL
https://hackerone.com/reports/622170
Severity score
4.8
Reporter
l00ph0le
Bounty paid
$100
Title
Insecure implementation of deserialization in funcster
URL
https://hackerone.com/reports/350401
Severity score
8.7
Reporter
greendog
Bounty paid
null
Title
pngcrush_measure_idat() off-by-one error (CVE-2015-2158)
URL
https://hackerone.com/reports/73429
Severity score
null
Reporter
geeknik
Bounty paid
null
Title
Remote Code Execution on contactws.contact-sys.com via SQL injection in TCertObject operation "Delete"
URL
https://hackerone.com/reports/816086
Severity score
10
Reporter
honoki
Bounty paid
$1,000
Title
https://mathfacts.khanacademy.org/ includes code from unprivileged localhost port
URL
https://hackerone.com/reports/331752
Severity score
null
Reporter
hanno
Bounty paid
null
Title
[node-df] RCE via insecure command concatenation
URL
https://hackerone.com/reports/703412
Severity score
8.4
Reporter
mik317
Bounty paid
null
Title
Java Deserialization RCE via JBoss JMXInvokerServlet/EJBInvokerServlet on card.starbucks.in
URL
https://hackerone.com/reports/153026
Severity score
null
Reporter
meals
Bounty paid
null
Title
Remote Code Execution (RCE) in a DoD website
URL
https://hackerone.com/reports/231926
Severity score
null
Reporter
joaomatosf
Bounty paid
null
Title
[logkitty] RCE via insecure command formatting
URL
https://hackerone.com/reports/825729
Severity score
7.8
Reporter
mik317
Bounty paid
null
Title
Remote code execution vulnerability on a DoD website
URL
https://hackerone.com/reports/212985
Severity score
null
Reporter
cha5m
Bounty paid
null
Title
Уязвимость получения всех номеров телефонов вк (по совместительству логинов профилей)
URL
https://hackerone.com/reports/67317
Severity score
null
Reporter
pisarenko
Bounty paid
$200
Title
Some HTML Tags are Getting Executed in com.nextcloud.client
URL
https://hackerone.com/reports/631227
Severity score
0
Reporter
ctulhu
Bounty paid
$50
Title
// (double slash) inside es6 template literals interpreted as an inline comment by the auto-minifier
URL
https://hackerone.com/reports/302289
Severity score
null
Reporter
veggie
Bounty paid
null
Title
ICQ Windows Application is Vulnerable to DLL Search Order Hijacking
URL
https://hackerone.com/reports/486502
Severity score
null
Reporter
cybercdh
Bounty paid
$100
Title
Publicly exposed SVN repository, ht.pornhub.com
URL
https://hackerone.com/reports/72243
Severity score
null
Reporter
mak
Bounty paid
$10,000
Title
Use After Free Vulnerability in PHP's GC algorithm and unserialize
URL
https://hackerone.com/reports/146233
Severity score
null
Reporter
evonide
Bounty paid
$1,000
Title
Arbitrary code execution via untrusted schemas in ajv
URL
https://hackerone.com/reports/897974
Severity score
null
Reporter
chalker
Bounty paid
null
Title
crash in openssl_random_pseudo_bytes function
URL
https://hackerone.com/reports/175263
Severity score
null
Reporter
jot
Bounty paid
$500
Title
Public Jenkins instance with /script enabled
URL
https://hackerone.com/reports/403402
Severity score
null
Reporter
smiegles
Bounty paid
$2,500
Title
integer overflow in quoted_printable_encode caused heap corruption
URL
https://hackerone.com/reports/159959
Severity score
null
Reporter
minhrau
Bounty paid
$500
Title
integer overflow in php_uuencode caused heap corruption
URL
https://hackerone.com/reports/159961
Severity score
null
Reporter
minhrau
Bounty paid
$500
Title
Remote code execution on an Army website
URL
https://hackerone.com/reports/188284
Severity score
null
Reporter
meals
Bounty paid
null
Title
Remote code execution vulnerability on a DoD website
URL
https://hackerone.com/reports/203600
Severity score
null
Reporter
mantis
Bounty paid
null
Title
Arbitrary code execution via untrusted schemas in is-my-json-valid
URL
https://hackerone.com/reports/894308
Severity score
null
Reporter
chalker
Bounty paid
null
Title
Double Free Corruption in wddx.c (extension)
URL
https://hackerone.com/reports/146255
Severity score
null
Reporter
hoangnguyen
Bounty paid
$500
Title
Server Side JavaScript Code Injection
URL
https://hackerone.com/reports/532667
Severity score
null
Reporter
phra
Bounty paid
$250
Title
heap overflow in php_ereg_replace function
URL
https://hackerone.com/reports/175264
Severity score
null
Reporter
jot
Bounty paid
$500
Title
Urgent: Server side template injection via Smarty template allows for RCE
URL
https://hackerone.com/reports/164224
Severity score
null
Reporter
yaworsk
Bounty paid
$400
Title
[windows-edge] RCE via insecure command formatting
URL
https://hackerone.com/reports/878420
Severity score
null
Reporter
mik317
Bounty paid
null
Title
ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize
URL
https://hackerone.com/reports/146235
Severity score
null
Reporter
evonide
Bounty paid
$1,000
Title
[git-lib] RCE via insecure command formatting
URL
https://hackerone.com/reports/718241
Severity score
6.4
Reporter
mik317
Bounty paid
null
Title
Writeup
URL
https://hackerone.com/reports/529371
Severity score
null
Reporter
bitk
Bounty paid
null
Title
OneLogin authentication bypass on WordPress sites via XMLRPC
URL
https://hackerone.com/reports/138869
Severity score
null
Reporter
jouko
Bounty paid
$7,000
Title
Stored self-XSS in mercantile.wordpress.org checkout
URL
https://hackerone.com/reports/230232
Severity score
null
Reporter
eidelweiss
Bounty paid
$275
Title
Remote Command Execution on a DoD website
URL
https://hackerone.com/reports/213776
Severity score
null
Reporter
t-pwn
Bounty paid
null
Title
Public instance of Jenkins on https://██████████/ with /script enabled
URL
https://hackerone.com/reports/768266
Severity score
null
Reporter
niteshsurana
Bounty paid
null
Title
Privacy policy contains hardcoded link using unencrypted HTTP
URL
https://hackerone.com/reports/365755
Severity score
null
Reporter
nightwatch-cybersecurity
Bounty paid
null
Title
bunyan - RCE via insecure command formatting
URL
https://hackerone.com/reports/902739
Severity score
null
Reporter
ahihi
Bounty paid
null
Title
RCE on █████ via CVE-2017-10271
URL
https://hackerone.com/reports/576887
Severity score
null
Reporter
erbbysam
Bounty paid
null
Title
(Pornhub & Youporn & Brazzers ANDROID APP) : Upload Malicious APK / Overrite Existing APK / Android BackOffice Access
URL
https://hackerone.com/reports/142352
Severity score
null
Reporter
dremos
Bounty paid
$1,500
Title
php_snmp_error() Format String Vulnerability
URL
https://hackerone.com/reports/127212
Severity score
null
Reporter
rewzilla
Bounty paid
$1,000
Title
Shell upload in partner service
URL
https://hackerone.com/reports/369557
Severity score
null
Reporter
danila
Bounty paid
$500
Title
Completed Compromise & Source Code Disclosure via Exposed Jenkins Dashboard at https://jenkins101.udemy.com
URL
https://hackerone.com/reports/182104
Severity score
null
Reporter
cha5m
Bounty paid
$300
Title
[script-manager] Unintended require
URL
https://hackerone.com/reports/660563
Severity score
null
Reporter
ermilov
Bounty paid
null
Title
Type confusion in FutureIter_throw() which may potentially lead to an arbitrary code execution
URL
https://hackerone.com/reports/182169
Severity score
null
Reporter
artem
Bounty paid
$500
Title
Remote Code Execution through Extension Bypass on Log Functionality
URL
https://hackerone.com/reports/841947
Severity score
8
Reporter
mayllart
Bounty paid
null
Title
Use-after-free vulnerability in SPL(ArrayObject, unserialize)
URL
https://hackerone.com/reports/114078
Severity score
null
Reporter
seanhn
Bounty paid
$1,000
Title
Child process environment injection via prototype pollution
URL
https://hackerone.com/reports/878181
Severity score
null
Reporter
coreyfarrell
Bounty paid
null
Title
Struct type confusion RCE
URL
https://hackerone.com/reports/181879
Severity score
null
Reporter
charliesome
Bounty paid
$18,000
Title
Text manipulation in https://checkout.rbk.money
URL
https://hackerone.com/reports/299034
Severity score
null
Reporter
arifkhan
Bounty paid
null
Title
RCE via Local File Read -> php unserialization-> XXE -> unpickling
URL
https://hackerone.com/reports/415501
Severity score
null
Reporter
iamnoooob
Bounty paid
null
Title
Remote file Inclusion - RFI in upload
URL
https://hackerone.com/reports/14092
Severity score
null
Reporter
coolboss
Bounty paid
null
Title
[Security Vulnerability Rocket.chat] HTML Injection into Email via Signup
URL
https://hackerone.com/reports/833470
Severity score
null
Reporter
steven_julian22
Bounty paid
null
Title
Reflected Filename Download
URL
https://hackerone.com/reports/54034
Severity score
null
Reporter
dsopas
Bounty paid
null
Title
tt-mac.i.mail.ru: Quagga 0.99.23.1 (Router) : Default password and default enable password
URL
https://hackerone.com/reports/62531
Severity score
null
Reporter
isox
Bounty paid
$200
Title
Format string vulnerability in zend_throw_or_error()
URL
https://hackerone.com/reports/106548
Severity score
null
Reporter
rewzilla
Bounty paid
$1,000
Title
Code injection in macOS Desktop Client
URL
https://hackerone.com/reports/633266
Severity score
3.8
Reporter
r3ggi-on-h1
Bounty paid
$250
Title
forum.getmonero.org Shell upload
URL
https://hackerone.com/reports/357858
Severity score
null
Reporter
kaulse
Bounty paid
null
Title
Java Deserialization RCE via JBoss on card.starbucks.in
URL
https://hackerone.com/reports/221294
Severity score
9
Reporter
joaomatosf
Bounty paid
null
Title
Your support community suffers from angularjs injection and must be fixed immediately [CRITICAL]
URL
https://hackerone.com/reports/274264
Severity score
6.5
Reporter
tolo7010
Bounty paid
$500
Title
loader.js is not secure
URL
https://hackerone.com/reports/629879
Severity score
null
Reporter
cdpython
Bounty paid
null
Title
Buffer overflow in HTTP url parsing functions
URL
https://hackerone.com/reports/121863
Severity score
null
Reporter
rc0r
Bounty paid
$1,000
Title
Сode injection host █████████
URL
https://hackerone.com/reports/954398
Severity score
null
Reporter
e3xpl0it
Bounty paid
null
Title
Arbitrary file upload when setting an avatar
URL
https://hackerone.com/reports/149268
Severity score
null
Reporter
strukt
Bounty paid
null
Title
Unrestricted file upload on [ambassador.mail.ru]
URL
https://hackerone.com/reports/854032
Severity score
9.7
Reporter
organdonor
Bounty paid
$3,000
Title
[gity] RCE via insecure command formatting
URL
https://hackerone.com/reports/730111
Severity score
6.4
Reporter
mik317
Bounty paid
null
Title
Unsecured DB instance
URL
https://hackerone.com/reports/189192
Severity score
null
Reporter
cyber-guard
Bounty paid
$5,000
Title
[commit-msg] RCE via insecure command formatting
URL
https://hackerone.com/reports/885031
Severity score
6.4
Reporter
mik317
Bounty paid
null
Title
Remote Code Execution (RCE) in a DoD website
URL
https://hackerone.com/reports/211381
Severity score
null
Reporter
joaomatosf
Bounty paid
null
Title
Remote Code Execution (RCE) in DoD Websites
URL
https://hackerone.com/reports/235605
Severity score
null
Reporter
joaomatosf
Bounty paid
null
Title
teach.udemy.com log poison vulnerability through wordpress debug.log being publically available
URL
https://hackerone.com/reports/60058
Severity score
null
Reporter
mthirup
Bounty paid
$150
Title
Monero Wallet Gui for Windows (Arbitrary Code Execution)
URL
https://hackerone.com/reports/630903
Severity score
null
Reporter
l00ph0le
Bounty paid
null
Title
[tree-kill] RCE via insecure command concatenation (only Windows)
URL
https://hackerone.com/reports/701183
Severity score
7
Reporter
mik317
Bounty paid
null
Title
[CRITICAL] Remote code execution on http://axa.dxi.eu
URL
https://hackerone.com/reports/418308
Severity score
null
Reporter
madrobot
Bounty paid
null
Title
Stored XSS on www.starbucks.com.sg/careers/career-center/career-landing-*
URL
https://hackerone.com/reports/507957
Severity score
6.5
Reporter
13ern
Bounty paid
$500
Title
Multiple vulnerabilities
URL
https://hackerone.com/reports/14248
Severity score
null
Reporter
pytesus
Bounty paid
null