readme.md

January 20, 2023 · View on GitHub

Title

Root Remote Code Execution on https://███

URL

https://hackerone.com/reports/632721

Severity score

null

Reporter

cdl

Bounty paid

null


Title

Java RMI (Remote Code Execution)

URL

https://hackerone.com/reports/163547

Severity score

null

Reporter

leba

Bounty paid

null


Title

http://fitter1.i.mail.ru/browser/ торчит Graphite в мир

URL

https://hackerone.com/reports/60573

Severity score

null

Reporter

isox

Bounty paid

$400


Title

potential RCE and XSS via file upload requiring user account and default settings

URL

https://hackerone.com/reports/678727

Severity score

8.8

Reporter

rcejules

Bounty paid

null


Title

URGENT - Subdomain Takeover in support.urbandictionary.com pointing to Zendesk

URL

https://hackerone.com/reports/103432

Severity score

null

Reporter

harry_mg

Bounty paid

null


Title

php mcrypt ext - In correct casting from size_t to int lead to heap overflow in mdecrypt_generic

URL

https://hackerone.com/reports/152400

Severity score

null

Reporter

minhrau

Bounty paid

$1,000


Title

SQL injection on contactws.contact-sys.com in TRateObject.AddForOffice in USER_ID parameter leads to remote code execution

URL

https://hackerone.com/reports/816560

Severity score

10

Reporter

honoki

Bounty paid

$1,000


Title

ownCloud 2.2.2.6192 DLL Hijacking Vulnerability

URL

https://hackerone.com/reports/151475

Severity score

null

Reporter

lionheartrox

Bounty paid

$50


Title

The “Malstaller” Attack, global hijacking of any installation process to achieve RCE with elevated privileges, Windows OS (vendor agnostic)

URL

https://hackerone.com/reports/165969

Severity score

null

Reporter

penrose

Bounty paid

null


Title

URGENT - SUBDOMAIN TAKEOVER ON TWITTER ACQ.

URL

https://hackerone.com/reports/44578

Severity score

null

Reporter

simon90

Bounty paid

null


Title

Image lib - unescaped file path

URL

https://hackerone.com/reports/250273

Severity score

null

Reporter

freetom

Bounty paid

null


Title

Windows Privilege Escalation: Malicious OpenSSL Engine

URL

https://hackerone.com/reports/608577

Severity score

7.8

Reporter

mirchr

Bounty paid

$200


Title

Prototype pollution attack (mixin-deep)

URL

https://hackerone.com/reports/311236

Severity score

1.8

Reporter

holyvier

Bounty paid

null


Title

Remote Code Execution on █████████

URL

https://hackerone.com/reports/962013

Severity score

null

Reporter

hzllaga

Bounty paid

null


Title

Уязвимость в Указание мест на фото + фича + хакинг

URL

https://hackerone.com/reports/66235

Severity score

null

Reporter

pisarenko

Bounty paid

$200


Title

Insecure implementation of deserialization in cryo

URL

https://hackerone.com/reports/350418

Severity score

8.7

Reporter

greendog

Bounty paid

null


Title

Remote command execution (RCE) vulnerability on a DoD website

URL

https://hackerone.com/reports/202652

Severity score

null

Reporter

japp1

Bounty paid

null


Title

Remote Code Execution (RCE) vulnerability in multiple DoD websites

URL

https://hackerone.com/reports/231687

Severity score

null

Reporter

joaomatosf

Bounty paid

null


Title

TOCTTOU bug in mrb_str_setbyte leading the memory corruption

URL

https://hackerone.com/reports/181893

Severity score

null

Reporter

raydot

Bounty paid

$20,000


Title

One Click Remote Code Injection - *.blog.newrelic.com

URL

https://hackerone.com/reports/941421

Severity score

null

Reporter

arsene_lupin

Bounty paid

$506.78


Title

Server-side include injection vulnerability in a DoD website

URL

https://hackerone.com/reports/192931

Severity score

null

Reporter

jutsuce

Bounty paid

null


Title

integer overflow in urlencode caused heap corruption

URL

https://hackerone.com/reports/159960

Severity score

null

Reporter

minhrau

Bounty paid

$500


Title

Local file read in image editor

URL

https://hackerone.com/reports/122475

Severity score

null

Reporter

sl1m

Bounty paid

$5,000


Title

Remote code execution (RCE) in multiple DoD websites

URL

https://hackerone.com/reports/226245

Severity score

null

Reporter

joaomatosf

Bounty paid

null


Title

Client-side Template Injection in Search, user email/token leak and maybe sandbox escape

URL

https://hackerone.com/reports/271960

Severity score

null

Reporter

europa

Bounty paid

$500


Title

Possible xWork classLoader RCE: shared.mail.ru

URL

https://hackerone.com/reports/67161

Severity score

null

Reporter

isox

Bounty paid

$200


Title

chrome://brave can still be navigated to, leading to RCE

URL

https://hackerone.com/reports/415178

Severity score

null

Reporter

qab

Bounty paid

$300


Title

Subdomain Takeover in http://assets.goubiquiti.com/

URL

https://hackerone.com/reports/109699

Severity score

null

Reporter

c1231665

Bounty paid

$500


Title

Code Injection Vulnerability in dot Package

URL

https://hackerone.com/reports/390929

Severity score

7.4

Reporter

cris_semmle

Bounty paid

null


Title

msilib.OpenDatabase Type Confusion

URL

https://hackerone.com/reports/167688

Severity score

null

Reporter

johnleitch

Bounty paid

$1,000


Title

Desktop app RCE (#276031 bypass)

URL

https://hackerone.com/reports/843171

Severity score

null

Reporter

ivarsvids

Bounty paid

null


Title

Content injection via URL parameter.

URL

https://hackerone.com/reports/263913

Severity score

null

Reporter

johnh4x0r

Bounty paid

null


Title

HTML Injection on airlink.ubnt.com

URL

https://hackerone.com/reports/226783

Severity score

null

Reporter

ruisilva

Bounty paid

$100


Title

DLL Hijacking in Synapse 2 CrashSender1402.exe via version.dll

URL

https://hackerone.com/reports/702252

Severity score

7.1

Reporter

cccaaasser

Bounty paid

$750


Title

Add arbitrary content to Password Reset Email

URL

https://hackerone.com/reports/244677

Severity score

null

Reporter

footstep

Bounty paid

null


Title

Remote code execution as root on [REDACTED]

URL

https://hackerone.com/reports/58914

Severity score

null

Reporter

agarri_fr

Bounty paid

$3,000


Title

RCE due to Web Console IP Whitelist bypass in Rails 4.0 and 4.1

URL

https://hackerone.com/reports/44513

Severity score

null

Reporter

joernchen

Bounty paid

$500


Title

Mercurial can be tricked into granting authorized users access to the Python debugger

URL

https://hackerone.com/reports/222020

Severity score

null

Reporter

claudijd

Bounty paid

$500


Title

Remote Code Execution (Reverse Shell) - File Manager

URL

https://hackerone.com/reports/768322

Severity score

5.1

Reporter

javakhishvili

Bounty paid

null


Title

DOM based XSS on

URL

https://hackerone.com/reports/139875

Severity score

null

Reporter

blackzero

Bounty paid

null


Title

Use of uninitialized memory in unserialize()

URL

https://hackerone.com/reports/195950

Severity score

null

Reporter

rc0r

Bounty paid

$500


Title

NULL pointer dereference in SimpleXMLElement::asXML()

URL

https://hackerone.com/reports/175262

Severity score

null

Reporter

jot

Bounty paid

$500


Title

Type confusion in partial.setstate, partial_repr, partial_call leads to memory corruption, reliable control flow hijack

URL

https://hackerone.com/reports/116286

Severity score

null

Reporter

nedw

Bounty paid

$1,000


Title

PHP openssl_x509_parse() Memory Corruption Vulnerability

URL

https://hackerone.com/reports/523

Severity score

null

Reporter

sesser

Bounty paid

$4,000


Title

RCE in profile picture upload

URL

https://hackerone.com/reports/135072

Severity score

null

Reporter

c666a323be94d57

Bounty paid

$2,500


Title

RCE on a Department of Defense website

URL

https://hackerone.com/reports/184279

Severity score

null

Reporter

dawgyg

Bounty paid

null


Title

[Simplenote for Windows] Client RCE via External JavaScript Inclusion leveraging Electron

URL

https://hackerone.com/reports/291539

Severity score

null

Reporter

ysx

Bounty paid

$250


Title

Server side request forgery on image upload for lists

URL

https://hackerone.com/reports/158016

Severity score

null

Reporter

eboda

Bounty paid

$50


Title

accounts.informatica.com - RCE due to exposed Groovy console

URL

https://hackerone.com/reports/672243

Severity score

null

Reporter

0ang3el

Bounty paid

null


Title

Remote Code Execution (RCE) in a DoD website

URL

https://hackerone.com/reports/213069

Severity score

null

Reporter

daveysec

Bounty paid

null


Title

RCE and Complete Server Takeover of http://www.█████.starbucks.com.sg/

URL

https://hackerone.com/reports/502758

Severity score

10

Reporter

spaceraccoon

Bounty paid

$4,000


Title

Remote client memory corruption in ssl_add_clienthello_tlsext()

URL

https://hackerone.com/reports/175766

Severity score

null

Reporter

guido

Bounty paid

null


Title

Comments Denial of Service in socialclub.rockstargames.com

URL

https://hackerone.com/reports/214370

Severity score

null

Reporter

ramsexy

Bounty paid

$500


Title

Remote Code Execution (RCE) in a DoD website

URL

https://hackerone.com/reports/248116

Severity score

null

Reporter

manoelt

Bounty paid

null


Title

URGENT - Subdomain Takeover on users.tweetdeck.com , the same issue of report #32825

URL

https://hackerone.com/reports/42236

Severity score

null

Reporter

missoum1307

Bounty paid

$420


Title

Regarding [CVE-2016-0752] Possible Information Leak Vulnerability in Action View

URL

https://hackerone.com/reports/113831

Severity score

null

Reporter

jyotisingh

Bounty paid

$1,500


Title

RCE on shared.mail.ru due to "widget" plugin

URL

https://hackerone.com/reports/518637

Severity score

10

Reporter

chaosbolt

Bounty paid

$10,000


Title

Remote Code Execution in Basecamp Windows Electron App

URL

https://hackerone.com/reports/1016966

Severity score

null

Reporter

co0sin

Bounty paid

$1,250


Title

Potential code injection in fun delete_directory

URL

https://hackerone.com/reports/250587

Severity score

null

Reporter

freetom

Bounty paid

null


Title

User Access Control Bypass Via Razer elevated service ( RzKLService.exe ) which loads exe in misconfigured way.

URL

https://hackerone.com/reports/769684

Severity score

null

Reporter

dredd_589

Bounty paid

$750


Title

[notevil] - Sandbox Escape Lead to RCE on Node.js and XSS in the Browser

URL

https://hackerone.com/reports/809012

Severity score

null

Reporter

phra

Bounty paid

null


Title

Remote Code Execution (RCE) in a DoD website

URL

https://hackerone.com/reports/212022

Severity score

null

Reporter

0daystolive

Bounty paid

null


Title

Remote Code Execution on Git.imgur-dev.com

URL

https://hackerone.com/reports/206227

Severity score

null

Reporter

orange

Bounty paid

$2,500


Title

[phpobject in cookie] Remote shell/command execution

URL

https://hackerone.com/reports/141956

Severity score

null

Reporter

static

Bounty paid

$20,000


Title

php curl ext size_t overflow lead to heap corruption

URL

https://hackerone.com/reports/152399

Severity score

null

Reporter

minhrau

Bounty paid

$1,000


Title

[treekill] RCE via insecure command concatenation (only Windows)

URL

https://hackerone.com/reports/703415

Severity score

7.3

Reporter

mik317

Bounty paid

null


Title

Возможность залить шелл на https://widget.operator.mail.ru

URL

https://hackerone.com/reports/304545

Severity score

null

Reporter

danila

Bounty paid

$500


Title

GMP Deserialization Type Confusion Vulnerability [MyBB <= 1.8.3 RCE Vulnerability]

URL

https://hackerone.com/reports/198734

Severity score

null

Reporter

ryat

Bounty paid

$1,500


Title

Arbitrary file read via ffmpeg HLS parser at https://www.flickr.com/photos/upload

URL

https://hackerone.com/reports/487008

Severity score

9.9

Reporter

asad0x01_

Bounty paid

$2,000


Title

links the user may download can be a malicious files

URL

https://hackerone.com/reports/182557

Severity score

null

Reporter

seifelsallamy

Bounty paid

null


Title

Explicit, dynamic render path: Dir. Trav + RCE

URL

https://hackerone.com/reports/46019

Severity score

8.6

Reporter

forced-request

Bounty paid

$500


Title

CSV Injection Via Student Password/Name Leads To Client Side RCE And Reading Client Files

URL

https://hackerone.com/reports/943255

Severity score

null

Reporter

demonia

Bounty paid

null


Title

Code injection in https://www.semrush.com

URL

https://hackerone.com/reports/723707

Severity score

null

Reporter

choan

Bounty paid

$500


Title

Email Server Compromised at secure.lahitapiola.fi

URL

https://hackerone.com/reports/177225

Severity score

null

Reporter

ak1t4

Bounty paid

$750


Title

[npm-git-publish] RCE via insecure command formatting

URL

https://hackerone.com/reports/730121

Severity score

6.8

Reporter

mik317

Bounty paid

null


Title

Unserialize leading to arbitrary PHP function invoke

URL

https://hackerone.com/reports/210741

Severity score

10

Reporter

someguyfromthepast

Bounty paid

$5,000


Title

newrelic.com rails directory traversal vuln

URL

https://hackerone.com/reports/134032

Severity score

null

Reporter

feelgood

Bounty paid

null


Title

Type confusion in wrap_decimal leading to memory corruption

URL

https://hackerone.com/reports/185051

Severity score

null

Reporter

raydot

Bounty paid

$18,000


Title

Phabricator Phame Blog Skins Local File Inclusion

URL

https://hackerone.com/reports/39428

Severity score

null

Reporter

nullsub

Bounty paid

$500


Title

Websites Can Run Arbitrary Code on Machines Running the 'PlayStation Now' Application

URL

https://hackerone.com/reports/873614

Severity score

9.6

Reporter

parsiya

Bounty paid

$15,000


Title

Windows builds with insecure path defaults (CVE-2019-1552)

URL

https://hackerone.com/reports/683318

Severity score

null

Reporter

mirchr

Bounty paid

$500


Title

Remote code execution by hijacking an unclaimed S3 bucket in Rocket.Chat's installation script.

URL

https://hackerone.com/reports/399166

Severity score

null

Reporter

edoverflow

Bounty paid

null


Title

Solution for h15411's CTF challenge

URL

https://hackerone.com/reports/415222

Severity score

9.8

Reporter

herrera

Bounty paid

null


Title

Integer overflow lead to heap corruption in sql_regcase

URL

https://hackerone.com/reports/159958

Severity score

null

Reporter

minhrau

Bounty paid

$500


Title

RCE on facebooksearch.algolia.com

URL

https://hackerone.com/reports/134321

Severity score

null

Reporter

michiel

Bounty paid

$500


Title

[meta-git] RCE via insecure command formatting

URL

https://hackerone.com/reports/728040

Severity score

6.2

Reporter

mik317

Bounty paid

null


Title

code injection, steam chat client

URL

https://hackerone.com/reports/411329

Severity score

null

Reporter

zemnmez

Bounty paid

$750


Title

newsroom.uber.com is vulnerable to 'SOME' XSS attack via plupload.flash.swf

URL

https://hackerone.com/reports/150375

Severity score

null

Reporter

jamesclyde

Bounty paid

$1,000


Title

(Authenticated) RCE by bypassing of the .htaccess blacklist

URL

https://hackerone.com/reports/228825

Severity score

9

Reporter

icewind1991

Bounty paid

null


Title

Several simple remote code execution in pdf-image

URL

https://hackerone.com/reports/781664

Severity score

null

Reporter

gabriel-kimiaie

Bounty paid

null


Title

Request Hijacking Vulnerability in RubyGems 2.6.11 and earlier

URL

https://hackerone.com/reports/218088

Severity score

null

Reporter

claudijd

Bounty paid

$1,000


Title

DLL Hijacking Vulnerability in GlassWireSetup.exe

URL

https://hackerone.com/reports/105977

Severity score

null

Reporter

ericlaw

Bounty paid

$100


Title

[H1-2006 2020] Connecting the dots to send hackers their Bug Bounty

URL

https://hackerone.com/reports/889886

Severity score

null

Reporter

akshansh

Bounty paid

null


Title

Remote code execution using render :inline

URL

https://hackerone.com/reports/113928

Severity score

null

Reporter

kratob2

Bounty paid

$1,500


Title

uber.com may RCE by Flask Jinja2 Template Injection

URL

https://hackerone.com/reports/125980

Severity score

null

Reporter

orange

Bounty paid

$10,000


Title

Trivial age-old heap overflow in 32-bit PHP

URL

https://hackerone.com/reports/112863

Severity score

null

Reporter

jbremer

Bounty paid

$500


Title

Remote Code Execution in Rocket.Chat Desktop

URL

https://hackerone.com/reports/276031

Severity score

null

Reporter

mattaustin

Bounty paid

null


Title

[blamer] RCE via insecure command formatting

URL

https://hackerone.com/reports/772448

Severity score

7.5

Reporter

mik317

Bounty paid

null


Title

Various vulnerabilities ultimately lead to attacker control over FliteThermostat server and access to internal accounting application source code

URL

https://hackerone.com/reports/504355

Severity score

null

Reporter

collinmay

Bounty paid

null


Title

PHP code injection at tz.mail.ru

URL

https://hackerone.com/reports/798135

Severity score

8.1

Reporter

cutoffurmind

Bounty paid

$3,000


Title

[create-git] RCE via insecure command formatting

URL

https://hackerone.com/reports/694471

Severity score

null

Reporter

mik317

Bounty paid

null


Title

Remote Code Execution in Slack desktop apps + bonus

URL

https://hackerone.com/reports/783877

Severity score

null

Reporter

oskarsv

Bounty paid

$1,750


Title

Code Injection Vulnerability in morgan Package

URL

https://hackerone.com/reports/390881

Severity score

6.8

Reporter

cris_semmle

Bounty paid

null


Title

Remote Code Execution in Wordpress Desktop

URL

https://hackerone.com/reports/301458

Severity score

null

Reporter

mattaustin

Bounty paid

$250


Title

RCE in ci.owncloud.com / ci.owncloud.org

URL

https://hackerone.com/reports/98559

Severity score

null

Reporter

tomdev

Bounty paid

null


Title

apps.owncloud.com: Malicious file upload leads to remote code execution

URL

https://hackerone.com/reports/84374

Severity score

null

Reporter

imadchabounia

Bounty paid

null


Title

Directory Traversal

URL

https://hackerone.com/reports/1092

Severity score

null

Reporter

nahamsec

Bounty paid

null


Title

Code Injection in macOS Desktop Client

URL

https://hackerone.com/reports/633262

Severity score

6.4

Reporter

r3ggi-on-h1

Bounty paid

$100


Title

another crash in locale_get_keywords function

URL

https://hackerone.com/reports/180116

Severity score

null

Reporter

jot

Bounty paid

$500


Title

Path traversal, SSTI and RCE on a MailRu acquisition

URL

https://hackerone.com/reports/536130

Severity score

9.8

Reporter

0xc0ffee

Bounty paid

$2,000


Title

Remote Unrestricted file Creation/Deletion and Possible RCE.

URL

https://hackerone.com/reports/191884

Severity score

null

Reporter

zigoo0

Bounty paid

null


Title

REMOTE CODE EXECUTION/LOCAL FILE INCLUSION/XSPA/SSRF, view-source:http://sb*.geo.sp1.yahoo.com/, 4/6/14, #SpringClean

URL

https://hackerone.com/reports/6674

Severity score

null

Reporter

nnwakelam

Bounty paid

$3,000


Title

[FG-VD-17-063] NextCloud Insufficient Attack Protection Vulnerability Notification

URL

https://hackerone.com/reports/232347

Severity score

null

Reporter

yzy9951

Bounty paid

$100


Title

In correct casting from size_t to int lead to heap overflow in mcrypt_generic

URL

https://hackerone.com/reports/152398

Severity score

null

Reporter

minhrau

Bounty paid

$1,000


Title

[git-promise] RCE via insecure command formatting

URL

https://hackerone.com/reports/728047

Severity score

6.2

Reporter

mik317

Bounty paid

null


Title

RCE via Print function [Simplenote 1.1.3 - Desktop app]

URL

https://hackerone.com/reports/358049

Severity score

null

Reporter

luigigubello

Bounty paid

$250


Title

SQL injection on contactws.contact-sys.com in TScenObject action ScenObjects leads to remote code execution

URL

https://hackerone.com/reports/816254

Severity score

10

Reporter

honoki

Bounty paid

$5,500


Title

Remote Code Execution in NovaStor NovaBACKUP DataCenter backup software (Hiback)

URL

https://hackerone.com/reports/138824

Severity score

null

Reporter

nyymi

Bounty paid

$100


Title

CSS Injection to disable app & potential message exfil

URL

https://hackerone.com/reports/679969

Severity score

4.3

Reporter

fletchto99

Bounty paid

$500


Title

Stack-based buffer overflow vulnerability in php_stream_zip_opener

URL

https://hackerone.com/reports/152278

Severity score

null

Reporter

knight9

Bounty paid

$1,000


Title

Code injection possible with malformed Nextcloud Talk chat commands

URL

https://hackerone.com/reports/851807

Severity score

8

Reporter

covert-spectre

Bounty paid

$3,000


Title

chrome://brave navigation from web

URL

https://hackerone.com/reports/415967

Severity score

null

Reporter

qab

Bounty paid

$650


Title

potential remote code execution with phar archive

URL

https://hackerone.com/reports/126652

Severity score

null

Reporter

vah13

Bounty paid

$500


Title

ICQ 10.0.12371 icq: Uri Handler '-testability' URL File Insecure Library Loading Code Execution Vulnerability

URL

https://hackerone.com/reports/406702

Severity score

7

Reporter

bigshape

Bounty paid

$500


Title

Use-after-free vulnerability in SPL(SplObjectStorage, unserialize)

URL

https://hackerone.com/reports/114079

Severity score

null

Reporter

seanhn

Bounty paid

$1,000


Title

crash in locale_compose() function

URL

https://hackerone.com/reports/180814

Severity score

null

Reporter

jot

Bounty paid

$500


Title

H1514 Server Side Template Injection in Return Magic email templates?

URL

https://hackerone.com/reports/423541

Severity score

null

Reporter

zombiehelp54

Bounty paid

$10,000


Title

Modify Host Header which is sent to email

URL

https://hackerone.com/reports/791293

Severity score

null

Reporter

codermak

Bounty paid

null


Title

[marketplace.informatica.com] - Template Injection

URL

https://hackerone.com/reports/299241

Severity score

null

Reporter

samengmg

Bounty paid

null


Title

bgplay.mail.ru

URL

https://hackerone.com/reports/122932

Severity score

null

Reporter

isox

Bounty paid

$200


Title

XML Parser Bug: XXE over which leads to RCE

URL

https://hackerone.com/reports/55431

Severity score

null

Reporter

sasi2103

Bounty paid

$700


Title

missing NULL check in dom_document_save_html

URL

https://hackerone.com/reports/175260

Severity score

null

Reporter

jot

Bounty paid

$500


Title

HTML Injection on https://www.mycrypto.com/

URL

https://hackerone.com/reports/326697

Severity score

null

Reporter

t-pwn

Bounty paid

null


Title

Review remote code execution in SwiftMailer

URL

https://hackerone.com/reports/194564

Severity score

null

Reporter

lukasreschke

Bounty paid

null


Title

Use after free vulnerability in mruby Array#to_h causing DOS possible RCE

URL

https://hackerone.com/reports/181321

Severity score

null

Reporter

isra17

Bounty paid

$20,000


Title

macaddress concatenates unsanitized input into exec() command

URL

https://hackerone.com/reports/319467

Severity score

10

Reporter

chalker

Bounty paid

null


Title

Remote code execution vulnerability on a DoD website

URL

https://hackerone.com/reports/192567

Severity score

null

Reporter

korprit

Bounty paid

null


Title

[FG-VD-17-115] Mail.ru's Amigo Browser DLL Pre-Loading Vulnerability Notification

URL

https://hackerone.com/reports/246663

Severity score

6.3

Reporter

kushal89shah

Bounty paid

null


Title

Remote File Upload Vulnerability in business-blog.zomato.com

URL

https://hackerone.com/reports/114389

Severity score

null

Reporter

missoum1307

Bounty paid

null


Title

Mass Assignment Vulnerability in partners.uber.com

URL

https://hackerone.com/reports/99424

Severity score

null

Reporter

rohk

Bounty paid

$1,000


Title

'Limited' RCE in certain places where Liquid is accepted

URL

https://hackerone.com/reports/98259

Severity score

null

Reporter

brakhane

Bounty paid

$1,500


Title

WordPress SOME bug in plupload.flash.swf leading to RCE

URL

https://hackerone.com/reports/134738

Severity score

null

Reporter

cure53

Bounty paid

$1,337


Title

EIP control using type confusion in json encoding

URL

https://hackerone.com/reports/112855

Severity score

null

Reporter

pakt_

Bounty paid

$1,000


Title

Control characters incorrectly handled on Crew Status Update

URL

https://hackerone.com/reports/232499

Severity score

null

Reporter

zuhnny1

Bounty paid

$250


Title

(Critical) Remote Code Execution Through Old TinyMCE upload bypass

URL

https://hackerone.com/reports/778629

Severity score

null

Reporter

konqi

Bounty paid

null


Title

crash in locale_get_keywords() when keyword value in locale string too long

URL

https://hackerone.com/reports/180115

Severity score

null

Reporter

jot

Bounty paid

$500


Title

Panorama UI XSS leads to Remote Code Execution via Kick/Disconnect Message

URL

https://hackerone.com/reports/631956

Severity score

null

Reporter

shayhelman

Bounty paid

$9,000


Title

Java Debug Console Provides Command Injection Without Privellage Esclation

URL

https://hackerone.com/reports/767482

Severity score

null

Reporter

rpbeast33

Bounty paid

null


Title

Docker image with FPM is vulnerable to CVE-2019-11043

URL

https://hackerone.com/reports/720306

Severity score

9.8

Reporter

beched

Bounty paid

$100


Title

Remote code executio in NPM package getcookies

URL

https://hackerone.com/reports/346516

Severity score

10

Reporter

tiblu

Bounty paid

null


Title

Arbitrary code execution in desktop client via OpenSSL config

URL

https://hackerone.com/reports/622170

Severity score

4.8

Reporter

l00ph0le

Bounty paid

$100


Title

Insecure implementation of deserialization in funcster

URL

https://hackerone.com/reports/350401

Severity score

8.7

Reporter

greendog

Bounty paid

null


Title

pngcrush_measure_idat() off-by-one error (CVE-2015-2158)

URL

https://hackerone.com/reports/73429

Severity score

null

Reporter

geeknik

Bounty paid

null


Title

Remote Code Execution on contactws.contact-sys.com via SQL injection in TCertObject operation "Delete"

URL

https://hackerone.com/reports/816086

Severity score

10

Reporter

honoki

Bounty paid

$1,000


Title

https://mathfacts.khanacademy.org/ includes code from unprivileged localhost port

URL

https://hackerone.com/reports/331752

Severity score

null

Reporter

hanno

Bounty paid

null


Title

[node-df] RCE via insecure command concatenation

URL

https://hackerone.com/reports/703412

Severity score

8.4

Reporter

mik317

Bounty paid

null


Title

Java Deserialization RCE via JBoss JMXInvokerServlet/EJBInvokerServlet on card.starbucks.in

URL

https://hackerone.com/reports/153026

Severity score

null

Reporter

meals

Bounty paid

null


Title

Remote Code Execution (RCE) in a DoD website

URL

https://hackerone.com/reports/231926

Severity score

null

Reporter

joaomatosf

Bounty paid

null


Title

[logkitty] RCE via insecure command formatting

URL

https://hackerone.com/reports/825729

Severity score

7.8

Reporter

mik317

Bounty paid

null


Title

Remote code execution vulnerability on a DoD website

URL

https://hackerone.com/reports/212985

Severity score

null

Reporter

cha5m

Bounty paid

null


Title

Уязвимость получения всех номеров телефонов вк (по совместительству логинов профилей)

URL

https://hackerone.com/reports/67317

Severity score

null

Reporter

pisarenko

Bounty paid

$200


Title

Some HTML Tags are Getting Executed in com.nextcloud.client

URL

https://hackerone.com/reports/631227

Severity score

0

Reporter

ctulhu

Bounty paid

$50


Title

// (double slash) inside es6 template literals interpreted as an inline comment by the auto-minifier

URL

https://hackerone.com/reports/302289

Severity score

null

Reporter

veggie

Bounty paid

null


Title

ICQ Windows Application is Vulnerable to DLL Search Order Hijacking

URL

https://hackerone.com/reports/486502

Severity score

null

Reporter

cybercdh

Bounty paid

$100


Title

Publicly exposed SVN repository, ht.pornhub.com

URL

https://hackerone.com/reports/72243

Severity score

null

Reporter

mak

Bounty paid

$10,000


Title

Use After Free Vulnerability in PHP's GC algorithm and unserialize

URL

https://hackerone.com/reports/146233

Severity score

null

Reporter

evonide

Bounty paid

$1,000


Title

Arbitrary code execution via untrusted schemas in ajv

URL

https://hackerone.com/reports/897974

Severity score

null

Reporter

chalker

Bounty paid

null


Title

crash in openssl_random_pseudo_bytes function

URL

https://hackerone.com/reports/175263

Severity score

null

Reporter

jot

Bounty paid

$500


Title

Public Jenkins instance with /script enabled

URL

https://hackerone.com/reports/403402

Severity score

null

Reporter

smiegles

Bounty paid

$2,500


Title

integer overflow in quoted_printable_encode caused heap corruption

URL

https://hackerone.com/reports/159959

Severity score

null

Reporter

minhrau

Bounty paid

$500


Title

integer overflow in php_uuencode caused heap corruption

URL

https://hackerone.com/reports/159961

Severity score

null

Reporter

minhrau

Bounty paid

$500


Title

Remote code execution on an Army website

URL

https://hackerone.com/reports/188284

Severity score

null

Reporter

meals

Bounty paid

null


Title

Remote code execution vulnerability on a DoD website

URL

https://hackerone.com/reports/203600

Severity score

null

Reporter

mantis

Bounty paid

null


Title

Arbitrary code execution via untrusted schemas in is-my-json-valid

URL

https://hackerone.com/reports/894308

Severity score

null

Reporter

chalker

Bounty paid

null


Title

Double Free Corruption in wddx.c (extension)

URL

https://hackerone.com/reports/146255

Severity score

null

Reporter

hoangnguyen

Bounty paid

$500


Title

Server Side JavaScript Code Injection

URL

https://hackerone.com/reports/532667

Severity score

null

Reporter

phra

Bounty paid

$250


Title

heap overflow in php_ereg_replace function

URL

https://hackerone.com/reports/175264

Severity score

null

Reporter

jot

Bounty paid

$500


Title

Urgent: Server side template injection via Smarty template allows for RCE

URL

https://hackerone.com/reports/164224

Severity score

null

Reporter

yaworsk

Bounty paid

$400


Title

[windows-edge] RCE via insecure command formatting

URL

https://hackerone.com/reports/878420

Severity score

null

Reporter

mik317

Bounty paid

null


Title

ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize

URL

https://hackerone.com/reports/146235

Severity score

null

Reporter

evonide

Bounty paid

$1,000


Title

[git-lib] RCE via insecure command formatting

URL

https://hackerone.com/reports/718241

Severity score

6.4

Reporter

mik317

Bounty paid

null


Title

Writeup

URL

https://hackerone.com/reports/529371

Severity score

null

Reporter

bitk

Bounty paid

null


Title

OneLogin authentication bypass on WordPress sites via XMLRPC

URL

https://hackerone.com/reports/138869

Severity score

null

Reporter

jouko

Bounty paid

$7,000


Title

Stored self-XSS in mercantile.wordpress.org checkout

URL

https://hackerone.com/reports/230232

Severity score

null

Reporter

eidelweiss

Bounty paid

$275


Title

Remote Command Execution on a DoD website

URL

https://hackerone.com/reports/213776

Severity score

null

Reporter

t-pwn

Bounty paid

null


Title

Public instance of Jenkins on https://██████████/ with /script enabled

URL

https://hackerone.com/reports/768266

Severity score

null

Reporter

niteshsurana

Bounty paid

null


Title

Privacy policy contains hardcoded link using unencrypted HTTP

URL

https://hackerone.com/reports/365755

Severity score

null

Reporter

nightwatch-cybersecurity

Bounty paid

null


Title

bunyan - RCE via insecure command formatting

URL

https://hackerone.com/reports/902739

Severity score

null

Reporter

ahihi

Bounty paid

null


Title

RCE on █████ via CVE-2017-10271

URL

https://hackerone.com/reports/576887

Severity score

null

Reporter

erbbysam

Bounty paid

null


Title

(Pornhub & Youporn & Brazzers ANDROID APP) : Upload Malicious APK / Overrite Existing APK / Android BackOffice Access

URL

https://hackerone.com/reports/142352

Severity score

null

Reporter

dremos

Bounty paid

$1,500


Title

php_snmp_error() Format String Vulnerability

URL

https://hackerone.com/reports/127212

Severity score

null

Reporter

rewzilla

Bounty paid

$1,000


Title

Shell upload in partner service

URL

https://hackerone.com/reports/369557

Severity score

null

Reporter

danila

Bounty paid

$500


Title

Completed Compromise & Source Code Disclosure via Exposed Jenkins Dashboard at https://jenkins101.udemy.com

URL

https://hackerone.com/reports/182104

Severity score

null

Reporter

cha5m

Bounty paid

$300


Title

[script-manager] Unintended require

URL

https://hackerone.com/reports/660563

Severity score

null

Reporter

ermilov

Bounty paid

null


Title

Type confusion in FutureIter_throw() which may potentially lead to an arbitrary code execution

URL

https://hackerone.com/reports/182169

Severity score

null

Reporter

artem

Bounty paid

$500


Title

Remote Code Execution through Extension Bypass on Log Functionality

URL

https://hackerone.com/reports/841947

Severity score

8

Reporter

mayllart

Bounty paid

null


Title

Use-after-free vulnerability in SPL(ArrayObject, unserialize)

URL

https://hackerone.com/reports/114078

Severity score

null

Reporter

seanhn

Bounty paid

$1,000


Title

Child process environment injection via prototype pollution

URL

https://hackerone.com/reports/878181

Severity score

null

Reporter

coreyfarrell

Bounty paid

null


Title

Struct type confusion RCE

URL

https://hackerone.com/reports/181879

Severity score

null

Reporter

charliesome

Bounty paid

$18,000


Title

Text manipulation in https://checkout.rbk.money

URL

https://hackerone.com/reports/299034

Severity score

null

Reporter

arifkhan

Bounty paid

null


Title

RCE via Local File Read -> php unserialization-> XXE -> unpickling

URL

https://hackerone.com/reports/415501

Severity score

null

Reporter

iamnoooob

Bounty paid

null


Title

Remote file Inclusion - RFI in upload

URL

https://hackerone.com/reports/14092

Severity score

null

Reporter

coolboss

Bounty paid

null


Title

[Security Vulnerability Rocket.chat] HTML Injection into Email via Signup

URL

https://hackerone.com/reports/833470

Severity score

null

Reporter

steven_julian22

Bounty paid

null


Title

Reflected Filename Download

URL

https://hackerone.com/reports/54034

Severity score

null

Reporter

dsopas

Bounty paid

null


Title

tt-mac.i.mail.ru: Quagga 0.99.23.1 (Router) : Default password and default enable password

URL

https://hackerone.com/reports/62531

Severity score

null

Reporter

isox

Bounty paid

$200


Title

Format string vulnerability in zend_throw_or_error()

URL

https://hackerone.com/reports/106548

Severity score

null

Reporter

rewzilla

Bounty paid

$1,000


Title

Code injection in macOS Desktop Client

URL

https://hackerone.com/reports/633266

Severity score

3.8

Reporter

r3ggi-on-h1

Bounty paid

$250


Title

forum.getmonero.org Shell upload

URL

https://hackerone.com/reports/357858

Severity score

null

Reporter

kaulse

Bounty paid

null


Title

Java Deserialization RCE via JBoss on card.starbucks.in

URL

https://hackerone.com/reports/221294

Severity score

9

Reporter

joaomatosf

Bounty paid

null


Title

Your support community suffers from angularjs injection and must be fixed immediately [CRITICAL]

URL

https://hackerone.com/reports/274264

Severity score

6.5

Reporter

tolo7010

Bounty paid

$500


Title

loader.js is not secure

URL

https://hackerone.com/reports/629879

Severity score

null

Reporter

cdpython

Bounty paid

null


Title

Buffer overflow in HTTP url parsing functions

URL

https://hackerone.com/reports/121863

Severity score

null

Reporter

rc0r

Bounty paid

$1,000


Title

Сode injection host █████████

URL

https://hackerone.com/reports/954398

Severity score

null

Reporter

e3xpl0it

Bounty paid

null


Title

Arbitrary file upload when setting an avatar

URL

https://hackerone.com/reports/149268

Severity score

null

Reporter

strukt

Bounty paid

null


Title

Unrestricted file upload on [ambassador.mail.ru]

URL

https://hackerone.com/reports/854032

Severity score

9.7

Reporter

organdonor

Bounty paid

$3,000


Title

[gity] RCE via insecure command formatting

URL

https://hackerone.com/reports/730111

Severity score

6.4

Reporter

mik317

Bounty paid

null


Title

Unsecured DB instance

URL

https://hackerone.com/reports/189192

Severity score

null

Reporter

cyber-guard

Bounty paid

$5,000


Title

[commit-msg] RCE via insecure command formatting

URL

https://hackerone.com/reports/885031

Severity score

6.4

Reporter

mik317

Bounty paid

null


Title

Remote Code Execution (RCE) in a DoD website

URL

https://hackerone.com/reports/211381

Severity score

null

Reporter

joaomatosf

Bounty paid

null


Title

Remote Code Execution (RCE) in DoD Websites

URL

https://hackerone.com/reports/235605

Severity score

null

Reporter

joaomatosf

Bounty paid

null


Title

teach.udemy.com log poison vulnerability through wordpress debug.log being publically available

URL

https://hackerone.com/reports/60058

Severity score

null

Reporter

mthirup

Bounty paid

$150


Title

Monero Wallet Gui for Windows (Arbitrary Code Execution)

URL

https://hackerone.com/reports/630903

Severity score

null

Reporter

l00ph0le

Bounty paid

null


Title

[tree-kill] RCE via insecure command concatenation (only Windows)

URL

https://hackerone.com/reports/701183

Severity score

7

Reporter

mik317

Bounty paid

null


Title

[CRITICAL] Remote code execution on http://axa.dxi.eu

URL

https://hackerone.com/reports/418308

Severity score

null

Reporter

madrobot

Bounty paid

null


Title

Stored XSS on www.starbucks.com.sg/careers/career-center/career-landing-*

URL

https://hackerone.com/reports/507957

Severity score

6.5

Reporter

13ern

Bounty paid

$500


Title

Multiple vulnerabilities

URL

https://hackerone.com/reports/14248

Severity score

null

Reporter

pytesus

Bounty paid

null